Page 3 of 14 results (0.004 seconds)

CVSS: 5.0EPSS: 8%CPEs: 3EXPL: 0

Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive. • http://pear.php.net/bugs/bug.php?id=6933 http://pear.php.net/package/Archive_Tar/download http://secunia.com/advisories/19011 http://www.hamid.ir/security/phptar.txt http://www.osvdb.org/23481 http://www.securityfocus.com/archive/1/425967/100/0/threaded http://www.securityfocus.com/bid/16805 http://www.vupen.com/english/advisories/2006/0728 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.4EPSS: 2%CPEs: 29EXPL: 1

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie. • https://www.exploit-db.com/exploits/43834 http://pear.php.net/package/LiveUser/download http://securityreason.com/securityalert/466 http://securitytracker.com/id?1015659 http://www.gulftech.org/?node=research&article_id=00103-02212006 http://www.securityfocus.com/archive/1/425711/100/0/threaded http://www.securityfocus.com/bid/16761 http://www.vupen.com/english/advisories/2006/0697 https://exchange.xforce.ibmcloud.com/vulnerabilities/24852 https://exchange.xforce.ibmcloud.com/vulnerabili •

CVSS: 7.5EPSS: 1%CPEs: 17EXPL: 0

Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers." • http://pear.php.net/package/Auth/download/1.2.4 http://pear.php.net/package/Auth/download/1.3.0r4 http://secunia.com/advisories/19008 http://secunia.com/advisories/19301 http://securitytracker.com/id?1015666 http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml http://www.securityfocus.com/archive/1/425796/100/0/threaded http://www.securityfocus.com/bid/16758 http://www.vupen.com/english/advisories/2006/0696 https://exchange.xforce.ibmcloud.com/vulnerabilities&# •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. • http://pear.php.net/package/Text_Password/download http://www.osvdb.org/23825 •