Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2018-16518

EPSS 2.16% · P85
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-16518

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Prim'X Zed! 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Prim'X Zed!是一款适用于多平台的文件压缩和加密工具。Prim'X Zed! FREE和Zed! Limited Edition都是它的不同版本。 Prim'X Zed! FREE 1.0 build 186及之前版本和Zed! Limited Edition 6.1 build 2208及之前版本中存在目录遍历漏洞,该漏洞源于watermark加载函数可以将可执行文件放在Startup文件夹中。攻击者可借助特制的ZED!容器利用该漏洞利用该漏洞在用户工作站上创建任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2018-16518

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-16518

登录查看更多情报信息。

Other References for CVE-2018-16518 (1)

Same Patch Batch · n/a · 2018-09-05 · 49 CVEs total

CVE-2018-16144Opsview Monitor 命令注入漏洞
CVE-2018-16147Opsview Monitor 跨站脚本漏洞
CVE-2018-16252FsPro Labs Event Log Explorer 安全漏洞
CVE-2018-16548ZZIPlib 安全漏洞
CVE-2018-16549HScripts PHP File Browser Script 路径遍历漏洞
CVE-2018-16550TeamViewer 安全漏洞
CVE-2018-16551LavaLite 跨站脚本漏洞
CVE-2018-16552MicroPyramid Django-CRM 跨站请求伪造漏洞
CVE-2018-16381e107 跨站脚本漏洞
CVE-2018-16145Opsview Monitor 安全漏洞
CVE-2018-16146Opsview Monitor 安全漏洞
CVE-2018-15918Jorani SQL注入漏洞
CVE-2018-15917Jorani 跨站脚本漏洞
CVE-2018-15684BTITeam XBTIT 安全漏洞
CVE-2018-15683BTITeam XBTIT 安全漏洞
CVE-2018-15682BTITeam XBTIT 跨站请求伪造漏洞
CVE-2018-15681BTITeam XBTIT 安全漏洞
CVE-2018-15680BTITeam XBTIT 安全漏洞
CVE-2018-15679BTITeam XBTIT 跨站脚本漏洞
CVE-2018-15678BTITeam XBTIT 跨站脚本漏洞

Showing top 20 of 49 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-16518

No comments yet


Leave a comment