Description


Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker to create or overwrite files by leading a user to expand a malicious ZIP archives.

References


http://www.eikisoft.com/release01.html

Release NotesVendor Advisory

Weaknesses



CWE-22

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

7.1 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2021-04-07T08:15:15.330

4 years ago

Last modified

2021-04-12T17:47:35.260

4 years ago