Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Gregory Beaver

#20943de 53,633
11.9CVSS total
Vulnerabilidades · 2
Média
2
PT-2007-3839
6.8
2007-05-22
Php · Pear · CVE-2007-2519
**Name of the Vulnerable Software and Affected Versions** PEAR versions 1.0 through 1.5.3 **Description** The issue allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the `install-as` attribute in the `file` element in `package.xml` 1.0 or the `as` attribute in the `install` element in `package.xml` 2.0. **Recommendations** For PEAR versions 1.0 through 1.5.3, consider restricting the use of the `install-as` attribute in `package.xml` 1.0 and the `as` attribute in `package.xml` 2.0 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2005-4853
5.1
2005-12-11
Php · Pear · CVE-2005-4154
**Name of the Vulnerable Software and Affected Versions** PEAR installer versions 1.4.2 and earlier **Description** The issue allows user-assisted attackers to execute arbitrary code via a crafted package. This can occur when the pear command is executed or when the Web/Gtk frontend is loaded. **Recommendations** For PEAR installer versions 1.4.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.