Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-20250 PoC — WinRar 路径遍历漏洞

Source
Associated Vulnerability
Title:WinRar 路径遍历漏洞 (CVE-2018-20250)
Description:WinRAR是一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRar中存在目录遍历漏洞。该漏洞源于WinRAR在解压处理ACE格式的文件过程中,未对ACE文件头结构中的“filename”字段进行充分过滤。攻击者可利用该漏洞以提升的权限执行任意代码。
Description
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
Readme
# CVE-2018-2025[0-3]

010 Editor template for ACE archive format & CVE-2018-2025[0-3]

ace.bt        010 editor template  
acefile.py    open source ace extractor, used for write template  
watchme.gif   demo  
wace269i      WinAce installer  
  
免责声明: 项目所有资源仅供技术研究使用。  
File Snapshot

[4.0K] /data/pocs/88c1a0d333d14de88b44b6cb32723f5f2c9d93c7 ├── [5.7K] ace.bt ├── [154K] acefile.py ├── [ 315] README.md ├── [3.9M] wace269i.exe └── [5.4M] watchme.gif 0 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.