Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-20250 PoC — WinRar 路径遍历漏洞

Source
Associated Vulnerability
Title:WinRar 路径遍历漏洞 (CVE-2018-20250)
Description:WinRAR是一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRar中存在目录遍历漏洞。该漏洞源于WinRAR在解压处理ACE格式的文件过程中,未对ACE文件头结构中的“filename”字段进行充分过滤。攻击者可利用该漏洞以提升的权限执行任意代码。
Description
CVE-2018-20250-WINRAR-ACE Exploit with a UI
Readme
# CVE-2018-20250-WINRAR-ACE-GUI

CVE-2018-20250-WINRAR-ACE Exploit with a UI.

Original Code : https://github.com/blau72/CVE-2018-20250-WinRAR-ACE
File Snapshot

[4.0K] /data/pocs/ffa6fbcd1398d2774784de4e53ecac9bec4a13dc ├── [4.0K] CVE-2018-20250-WinRAR-ACE-master │   └── [4.0K] CVE-2018-20250-WinRAR-ACE-master │   ├── [6.6K] AceFile.cs │   ├── [6.2K] AceVolume.cs │   ├── [ 787] README.md │   └── [ 415] Utils.cs ├── [4.3K] CVE-2018-20250-WinRAR-ACE-master.zip ├── [ 147] README.md ├── [4.0K] WinRar_Exploit │   ├── [6.6K] AceFile.cs │   ├── [6.2K] AceVolume.cs │   ├── [ 184] App.config │   ├── [ 373] App.xaml │   ├── [ 330] App.xaml.cs │   ├── [ 45K] e3830e57efb7c1669689e757a29f7810_258526e2b3b3_t.png │   ├── [1.8K] Help.xaml │   ├── [ 587] Help.xaml.cs │   ├── [ 16K] index.png │   ├── [ 32K] lucii.png │   ├── [2.5K] MainWindow.xaml │   ├── [1.2K] MainWindow.xaml.cs │   ├── [ 234] packages.config │   ├── [4.0K] Properties │   │   ├── [2.3K] AssemblyInfo.cs │   │   ├── [2.7K] Resources.Designer.cs │   │   ├── [5.4K] Resources.resx │   │   ├── [1.0K] Settings.Designer.cs │   │   └── [ 195] Settings.settings │   ├── [ 415] Utils.cs │   └── [5.1K] WinRar_Exploit.csproj └── [1.2K] WinRar_Exploit.sln 4 directories, 27 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.