CVE-2003-0282
UnZip 5.50 - Directory Traversal via Invalid Dot Character Filtering
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2003-0282. PoCs published by Jelmer, sionnx.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in Info-ZIP UnZip, where encoded characters in '../' sequences allow arbitrary file extraction. No actual exploit code is present, only a description and reference link.
Description
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
Exploits (2)
The provided text describes a directory traversal vulnerability in Info-ZIP UnZip, where encoded characters in '../' sequences allow arbitrary file extraction. No actual exploit code is present, only a description and reference link.
This repository contains the source code for Info-ZIP's UnZip utility, version 5.51, which includes fixes for multiple security vulnerabilities, including CVE-2003-0282. The code demonstrates the vulnerability and its patches, particularly focusing on path traversal and symlink security issues.