vendor:
CAM UnZip
by:
hyp3rlinx
5.5
CVSS
MEDIUM
Archive Path Traversal
22
CWE
Product Name: CAM UnZip
Affected Version From: CAM UnZip v5.1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:a:camunzip:cam_unzip:5.1:*:*:*:*:*:*:*
Platforms Tested: Windows 7
CAM UnZip Archive Path Traversal
CAM UnZip fails to check that the paths of the files in the archive do not engage in path traversal when uncompressing the archive files. Specially crafted files in the archive containing '..' in file name can overwrite files on the filesystem by backtracking or allow attackers to place malicious files on system outside of the target unzip directory which may lead to remote command execution exploits etc...
Mitigation:
No patch or mitigation available