Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
archives.neohapsis.com/archives/fulldisclosure/2006-06/0196.html
lists.grok.org.uk/pipermail/full-disclosure/2006-June/046810.html
secunia.com/advisories/20575
winscp.net/eng/docs/history#3.8.2
www.kb.cert.org/vuls/id/912588
www.securityfocus.com/bid/18384
www.vupen.com/english/advisories/2006/2289
exchange.xforce.ibmcloud.com/vulnerabilities/27075