WinRAR Format String Vulnerability

WinRAR Format String Vulnerability

CVE-2005-3262 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

Learn more about our Web Application Penetration Testing UK.