Perl Archive Zip Directory Traversal File Overwrite

Strike ID:
E18-5i981
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a directory traversal vulnerability in Perl Archive. The filename field of zip files is not sanitized for directory traversal characters. Files unzipped with Perl Archive may overwrite files in the location specified in the directory traversal. An attacker can exploit this by sending a specially crafted zip file to the target and enticing them to use Perl Archive to unzip the file. Successful exploitation may result in arbitrary file overwrite.

CVE

References

Bid