source: https://www.securityfocus.com/bid/18384/info
WinSCP is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to upload arbitrary files to a victim user's computer or to download arbitrary files from the victim's computer in the context of the vulnerable application.
This issue affects version 3.8.1; earlier versions may also be vulnerable.
download malware.exe