漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation feature enabled, and a product user tries to extract an archive file which has a crafted file name, then the archived files may be extracted to an unexpected folder.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Chitora Lhaz 路径遍历漏洞
Vulnerability Description
Chitora Lhaz是日本Chitora公司的一款支持多种压缩格式文件创建与解压缩的Windows压缩工具。 Chitora Lhaz存在路径遍历漏洞,该漏洞源于自动文件夹创建功能存在路径遍历问题,当配置启用该功能且用户尝试解压具有特制文件名的归档文件时,可能导致文件被解压到意外文件夹。
CVSS Information
N/A
Vulnerability Type
N/A