ezb systems ultraiso 8.0.1392 - Directory Traversal

Author: Sowhat
type: remote
platform: windows
port: 
date_added: 2006-04-28  
date_updated: 2013-08-27  
verified: 1  
codes: CVE-2006-2099;OSVDB-25077  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 27758.txt  
source: https://www.securityfocus.com/bid/17724/info

Reportedly, an attacker can carry out attacks using directory-traversal strings. These issues occur when the application processes malicious archives.

A successful attack can allow the attacker to place potentially malicious files and to overwrite files on a computer in the context of the user running the affected application. A successful exploit may aid in further attacks.

This issue affects UltraISO version 8.0.0. 1392; other versions may also be affected.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27746.iso.bin