Stats
- First seen
- June 2022
- Last seen
- October 2026
Description
Detects an archive exploiting CVE-2020-28949, the Perl archive module flaw used by a Metasploit module to write files outside the extraction directory. The rule matches the crafted traversal structures that the exploit uses to plant files on the target.