mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
21 lines
811 B
Markdown
21 lines
811 B
Markdown
![]() |
### [CVE-2015-1197](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1197)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/Live-Hack-CVE/CVE-2015-1197
|
||
|
- https://github.com/Live-Hack-CVE/CVE-2017-7516
|
||
|
- https://github.com/fokypoky/places-list
|
||
|
|