Lucene search

K
cve[email protected]CVE-2006-0926
HistoryFeb 28, 2006 - 11:02 a.m.

CVE-2006-0926

2006-02-2811:02:00
web.nvd.nist.gov
24
cve-2006-0926
allume
zipmagic
directory traversal
vulnerability
remote attack
crafted pathnames
archive

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%

Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

Affected configurations

NVD
Node
smithmicrostuffit_deluxeMatch9.0
OR
smithmicrostuffit_expanderMatch9.0.0.21_engine_9.0.0.21
OR
smithmicrostuffit_standardMatch9.0
OR
smithmicrozipmagic_deluxeMatch9.0

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%

Related for CVE-2006-0926