mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 01:04:30 +00:00
841 B
841 B
CVE-2019-14751
Description
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
POC
Reference
- https://github.com/mssalvatore/CVE-2019-14751_PoC
- https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/