PT-2007-2854 · Php · Php

Published

2007-03-14

·

Updated

2011-05-24

·

CVE-2007-1460

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 4.4.7 PHP versions 5.2.0 and 5.2.1
Description The issue concerns the zip:// URL wrapper provided by the PECL zip extension in PHP, which fails to implement safemode or open basedir checks. This allows remote attackers to read ZIP archives located outside of the intended directories.
Recommendations For PHP versions prior to 4.4.7, update to version 4.4.7 or later. For PHP versions 5.2.0 and 5.2.1, update to a version later than 5.2.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1460

Affected Products

Php