Exploit Unreal Commander 0.92 - ZIP / RAR Archive Handling Traversal Arbitrary File Overwrite

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
30521
Проверка EDB
  1. Пройдено
Автор
GYNVAEL COLDWIND
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2007-4545
Дата публикации
2007-08-23
Код:
source: https://www.securityfocus.com/bid/25419/info

Unreal Commander is prone to multiple remote vulnerabilities when handling malformed ZIP and RAR archives. These vulnerabilities include a directory-traversal vulnerability, an information-disclosure vulnerability, and a filename-spoofing vulnerability.

An attacker can exploit these issues to compromise the affected computer, overwrite arbitrary files, and obtain sensitive information. Exploits of these issues may lead to other attacks.

Unreal Commander 0.92 (build 565) and 0.92 (build 573) are vulnerable; prior versions may also be affected. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30521-1.zip
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30521-2.zip
 
Источник
www.exploit-db.com

Похожие темы