Path traversal in DFArc - CVE-2018-0496
Published: July 3, 2018 / Updated: July 4, 2018
DFArc
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to path traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version). A remote unauthenticated attacker can conduct directory traversal attack, bypass security restrictions and overwrite arbitrary files on the user's system.