Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dzip | Evan_wagner | * | 2.0 (including) |
Dzip | Evan_wagner | 2.1 (including) | 2.1 (including) |
Dzip | Evan_wagner | 2.2 (including) | 2.2 (including) |
Dzip | Evan_wagner | 2.3 (including) | 2.3 (including) |
Dzip | Evan_wagner | 2.4 (including) | 2.4 (including) |
Dzip | Evan_wagner | 2.5 (including) | 2.5 (including) |
Dzip | Evan_wagner | 2.6 (including) | 2.6 (including) |
Dzip | Evan_wagner | 2.8 (including) | 2.8 (including) |
Dzip | Evan_wagner | 2.21 (including) | 2.21 (including) |
Dzip | Evan_wagner | 2.51 (including) | 2.51 (including) |
Dzip | Evan_wagner | 2.55 (including) | 2.55 (including) |
Dzip | Evan_wagner | 2.81 (including) | 2.81 (including) |
Dzip | Evan_wagner | 2.82 (including) | 2.82 (including) |
Dzip | Evan_wagner | 2.83 (including) | 2.83 (including) |
Dzip | Evan_wagner | 2.84 (including) | 2.84 (including) |