Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6j2-5wf7-xffq

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

EPSS

Процентиль: 77%
0.01126
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

nvd
больше 18 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

debian
больше 18 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP befor ...

EPSS

Процентиль: 77%
0.01126
Низкий