Snyk Security team

9 exploits Active since Jul 2018
CVE-2018-1002203 WRITEUP MEDIUM WRITEUP
unzipper <0.8.13 - Path Traversal
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002204 WRITEUP MEDIUM WRITEUP
adm-zip <0.4.9 - Path Traversal
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002205 WRITEUP MEDIUM WRITEUP
DotNetZip.Semvered <1.11.0 - Path Traversal
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002206 WRITEUP MEDIUM WRITEUP
SharpCompress <0.21.0 - Path Traversal
SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002207 WRITEUP MEDIUM WRITEUP
Archiver < 2.0 - Path Traversal
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002208 WRITEUP MEDIUM WRITEUP
SharpZipLib <1.0 RC1 - Path Traversal
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2018-1002209 WRITEUP MEDIUM WRITEUP
QuaZIP <0.7.6 - Path Traversal
QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS 5.5
CVE-2021-26539 WRITEUP MEDIUM WRITEUP
Apostrophe Technologies sanitize-html <2.3.1 - Info Disclosure
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
CVSS 5.3
CVE-2021-26540 WRITEUP MEDIUM WRITEUP
Apostrophe Technologies sanitize-html <2.3.2 - Open Redirect
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
CVSS 5.3