Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g59c-vc6x-27p6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

EPSS

Процентиль: 75%
0.00953
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

nvd
больше 18 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

debian
больше 18 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP ...

EPSS

Процентиль: 75%
0.00953
Низкий