{"api_version":"1","generated_at":"2026-07-23T04:33:23+00:00","cve":"CVE-2005-4533","urls":{"html":"https://cve.report/CVE-2005-4533","api":"https://cve.report/api/cve/CVE-2005-4533.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4533","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4533"},"summary":{"title":"CVE-2005-4533","description":"Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via \"getopt\" style argument specifications, which are not filtered.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-28 01:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/18236","name":"http://secunia.com/advisories/18236","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Gentoo update for scponly","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23875","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23875","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18223","name":"http://secunia.com/advisories/18223","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - scponly Privilege Escalation and Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16051","name":"http://www.securityfocus.com/bid/16051","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SCPOnly Multiple Local Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://sublimation.org/scponly/#relnotes","name":"http://sublimation.org/scponly/#relnotes","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"scponly homepage","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  scponly: Multiple privilege escalation issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4533","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4533","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"3.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"3.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"3.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scponly","cpe5":"scponly","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:05.517Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"18223","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18223"},{"name":"16051","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16051"},{"name":"18236","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18236"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sublimation.org/scponly/#relnotes"},{"name":"GLSA-200512-17","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml"},{"name":"scponly-escape-shell-restrictions(23875)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23875"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via \"getopt\" style argument specifications, which are not filtered."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-11T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"18223","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18223"},{"name":"16051","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16051"},{"name":"18236","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18236"},{"tags":["x_refsource_CONFIRM"],"url":"http://sublimation.org/scponly/#relnotes"},{"name":"GLSA-200512-17","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml"},{"name":"scponly-escape-shell-restrictions(23875)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23875"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4533","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via \"getopt\" style argument specifications, which are not filtered."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18223","refsource":"SECUNIA","url":"http://secunia.com/advisories/18223"},{"name":"16051","refsource":"BID","url":"http://www.securityfocus.com/bid/16051"},{"name":"18236","refsource":"SECUNIA","url":"http://secunia.com/advisories/18236"},{"name":"http://sublimation.org/scponly/#relnotes","refsource":"CONFIRM","url":"http://sublimation.org/scponly/#relnotes"},{"name":"GLSA-200512-17","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200512-17.xml"},{"name":"scponly-escape-shell-restrictions(23875)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23875"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4533","datePublished":"2005-12-28T01:00:00.000Z","dateReserved":"2005-12-28T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:05.517Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-28 01:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:2.0:*:*:*:*:*:*:*","matchCriteriaId":"A74980DC-9A5B-4959-8193-1D7BE85CAEA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:2.1:*:*:*:*:*:*:*","matchCriteriaId":"0863C35F-6061-426B-B656-E7B4A02D3E95"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:3.0:*:*:*:*:*:*:*","matchCriteriaId":"32B689CE-F02B-4315-9E74-BC360EAFB937"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:3.5:*:*:*:*:*:*:*","matchCriteriaId":"0C3262EA-F693-439B-922D-3F0DA09D0753"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:3.8:*:*:*:*:*:*:*","matchCriteriaId":"B37D1F24-B45D-4217-972E-61BED886275A"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:3.9:*:*:*:*:*:*:*","matchCriteriaId":"71D3E1C8-ADCB-4A5F-8078-66942E36DF6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:3.11:*:*:*:*:*:*:*","matchCriteriaId":"190FB980-F17F-43A9-8DA4-B2A99E29DF3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:scponly:scponly:4.1:*:*:*:*:*:*:*","matchCriteriaId":"298502A9-5E53-4CBE-BCCA-6D86EFDD3BF3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4533","Ordinal":"1","Title":"CVE-2005-4533","CVE":"CVE-2005-4533","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4533","Ordinal":"1","NoteData":"Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via \"getopt\" style argument specifications, which are not filtered.","Type":"Description","Title":"CVE-2005-4533"},{"CveYear":"2005","CveId":"4533","Ordinal":"2","NoteData":"2005-12-27","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4533","Ordinal":"3","NoteData":"2017-10-10","Type":"Other","Title":"Modified"}]}}}