RCE in EventLog Analyzer(ZVE-2020-6448)

RCE in EventLog Analyzer(ZVE-2020-6448)

No account required, and it not just for RCE.you can upload any logs with this vulnerability.

In shortly,EventLog Analyzer Affected by Zip-Slip-Vulnerability.But it’s hard to exploit, revese of the log collector takes me a few days, and it’s hard to explain, just read my exploit code.

image-20201228170958445

image-20201228182312660

image-20201228182933955