SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Allegra extractFileFromZip Directory Traversal 1

Category: WEB-ATTACKS      

The specific flaw exists within the implementation of the extractFileFromZip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process.


Relevant Information