Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.
Cite this page
CVE-2007-4909. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2007-4909
Use CWE-264, Winscp vendor hub and Winscp product page to widen CVE-2007-4909 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-3331, CVE-2020-28864 and CVE-2018-20684 for nearby disclosures in the same product family.