Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2023-39139

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
Attacker Value
Unknown

CVE-2023-39137

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Attacker Value
Unknown

CVE-2023-39136

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Attacker Value
Unknown

CVE-2023-25484

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.
Attacker Value
Unknown

CVE-2023-25490

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
Attacker Value
Unknown

CVE-2022-36943

Disclosure Date: January 03, 2023 (last updated February 24, 2025)
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
Attacker Value
Unknown

CVE-2020-28422

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
All versions of package git-archive are vulnerable to Command Injection via the exports function.
Attacker Value
Unknown

CVE-2020-7664

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Attacker Value
Unknown

CVE-2020-7668

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Attacker Value
Unknown

CVE-2018-10860

Disclosure Date: June 29, 2018 (last updated November 26, 2024)
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
0