WinISO Directory Traversal Vulnerability

This issue can be exploited by creating a malicious archive file that includes files with directory-traversal strings ('../') in the names.

The following proof of concept is available:


 

Privacy Statement
Copyright 2010, SecurityFocus