Skip to content
This repository has been archived by the owner on Jan 3, 2024. It is now read-only.

zip_slip #42

Open
QiAnXinCodeSafe opened this issue May 15, 2019 · 0 comments
Open

zip_slip #42

QiAnXinCodeSafe opened this issue May 15, 2019 · 0 comments

Comments

@QiAnXinCodeSafe
Copy link

图片
Unpack() does not verify the entry name when extracting the file. When the compressed file is constructed by extracting the attacker (with “../” in the entry name), it will overwrite the important file outside the specified directory.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant