Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2023-39139
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
0
Attacker Value
Unknown
CVE-2023-39137
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
0
Attacker Value
Unknown
CVE-2023-39136
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
0
Attacker Value
Unknown
CVE-2023-25484
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.
0
Attacker Value
Unknown
CVE-2023-25490
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
0
Attacker Value
Unknown
CVE-2022-36943
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
0
Attacker Value
Unknown
CVE-2020-28422
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
All versions of package git-archive are vulnerable to Command Injection via the exports function.
0
Attacker Value
Unknown
CVE-2020-7664
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
0
Attacker Value
Unknown
CVE-2020-7668
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
0
Attacker Value
Unknown
CVE-2018-10860
Disclosure Date: June 29, 2018 (last updated November 26, 2024)
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
0