Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitrary directories via a .. (dot dot) in the filename of a file that is stored in a (1) RAR (.rar), (2) TAR (.tar), (3) ZIP (.zip), (4) GZ (.gz), or (5) JAR (.jar) archive.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BitZipper 文档解压 目录遍历漏洞
Vulnerability Description
BitZipper是Windows平台的高级数据压缩工具。 BitZipper在解压RAR(.rar)、TAR(.tar)、ZIP(.zip)、TAR.GZ(tar.gz)、GZ(.gz)或JAR(.jar)格式压缩文件时存在输入验证错误,允许攻击者使用"../"目录遍历序列将文件解压到指定目录之外的任意位置。
CVSS Information
N/A
Vulnerability Type
N/A