patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
This program is an script developed in Python which exploit the ACE vulnerability on WinRar - Vulnerability CVE-2018-20250
POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code.
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
Oracle-WebLogic-CVE-2017-10271
CVE-2018-20250-WINRAR-ACE Exploit with a UI
Python tool exploiting CVE-2018-20250 found by CheckPoint folks
WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the people didn't update winrar so they are vulnerable in this Absolute Path Traversal bug [CVE-2018-20250]
Simple POC to leverage CVE-2018-20250 from inside an EXE
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
A version of the binary patched to address CVE-2018-20250
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
This is a exp of CVE-2018-15473