Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxv8-pv43-57x5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

PEAR core file overwrite vulnerability

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

Пакеты

Наименование

pear/pear

composer
Затронутые версииВерсия исправления

<= 1.10.1

Отсутствует

EPSS

Процентиль: 91%
0.0754
Низкий

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

CVSS3: 3.4
redhat
больше 8 лет назад

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

CVSS3: 7.5
nvd
больше 8 лет назад

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

CVSS3: 7.5
debian
больше 8 лет назад

PECL in the download utility class in the Installer in PEAR Base Syste ...

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость библиотеки классов PHP PEAR, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 91%
0.0754
Низкий

7.5 High

CVSS3

Дефекты

CWE-74