5

CVE-2006-2520

Exploit
Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitrary directories via a ..  (dot dot) in the filename of a file that is stored in a (1) RAR (.rar), (2) TAR (.tar), (3) ZIP (.zip), (4) GZ (.gz), or (5) JAR (.jar) archive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitberry SoftwareBitzipper Version3.2
Bitberry SoftwareBitzipper Version3.2.1
Bitberry SoftwareBitzipper Version3.3
Bitberry SoftwareBitzipper Version3.4
Bitberry SoftwareBitzipper Version3.4.1
Bitberry SoftwareBitzipper Version4.0
Bitberry SoftwareBitzipper Version4.1
Bitberry SoftwareBitzipper Version4.1.1
Bitberry SoftwareBitzipper Version4.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://hamid.ir/security/bitzipper.txt
Vendor Advisory
Exploit
http://secunia.com/advisories/20207
Vendor Advisory
http://securitytracker.com/id?1016132
http://www.osvdb.org/25693
http://www.securityfocus.com/archive/1/434713/100/0/threaded
http://www.securityfocus.com/bid/18065
http://www.vupen.com/english/advisories/2006/1907
https://exchange.xforce.ibmcloud.com/vulnerabilities/26626