Vulnerability Details CVE-2005-0331
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.7%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2005-0331
-
cpe:2.3:a:rarlab:winrar:3.0.0
-
cpe:2.3:a:rarlab:winrar:3.10
-
cpe:2.3:a:rarlab:winrar:3.10_beta3
-
cpe:2.3:a:rarlab:winrar:3.10_beta5
-
cpe:2.3:a:rarlab:winrar:3.11
-
cpe:2.3:a:rarlab:winrar:3.20
-
cpe:2.3:a:rarlab:winrar:3.40
-
cpe:2.3:a:rarlab:winrar:3.41
-
cpe:2.3:a:rarlab:winrar:3.42