QuickZip Multiple Directory Traversal Vulnerabilities
BID:18722
CVE-2006-3326 |Info
QuickZip Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 18722 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2006 12:00AM |
| Updated: | Jun 29 2006 08:14PM |
| Credit: | Claus Berghammer is credited with the discovery of this vulnerability. |
| Vulnerable: |
QuickZip QuickZip 3.6.3 |
| Not Vulnerable: | |
Discussion
QuickZip Multiple Directory Traversal Vulnerabilities
QuickZip is prone to multiple directory-traversal vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to place malicious files and to overwrite files in arbitrary locations on the vulnerable system, in the context of the user running the application. Successful exploits may aid in further attacks.
QuickZip is prone to multiple directory-traversal vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to place malicious files and to overwrite files in arbitrary locations on the vulnerable system, in the context of the user running the application. Successful exploits may aid in further attacks.
Exploit / POC
QuickZip Multiple Directory Traversal Vulnerabilities
Attackers may exploit these issues by creating malicious TAR, JAR, or GZ files that include files with directory-traversal strings ('../') in the names.
Attackers may exploit these issues by creating malicious TAR, JAR, or GZ files that include files with directory-traversal strings ('../') in the names.
Solution / Fix
QuickZip Multiple Directory Traversal Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].