Exploit Winace UnAce 1.x - ACE Archive Directory Traversal

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
25150
Проверка EDB
  1. Пройдено
Автор
ULF HARNHAMMAR
Тип уязвимости
REMOTE
Платформа
LINUX
CVE
cve-2005-0161
Дата публикации
2005-02-23
Код:
source: https://www.securityfocus.com/bid/12628/info

A remotely exploitable client-side directory-traversal vulnerability affects Winace unace. The application fails to properly sanitize file and directory names contained within malicious ACE format archives.

An attacker may leverage this issue by distributing malicious ACE archives to unsuspecting users. This issue will allow an attacker to write files to arbitrary locations on the filesystem with the privileges of an unsuspecting user that extracts the malicious ACE archive.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/25150.zip
 
Источник
www.exploit-db.com

Похожие темы