1 results (0.002 seconds)

CVSS: 5.0EPSS: 8%CPEs: 3EXPL: 0

Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive. • http://pear.php.net/bugs/bug.php?id=6933 http://pear.php.net/package/Archive_Tar/download http://secunia.com/advisories/19011 http://www.hamid.ir/security/phptar.txt http://www.osvdb.org/23481 http://www.securityfocus.com/archive/1/425967/100/0/threaded http://www.securityfocus.com/bid/16805 http://www.vupen.com/english/advisories/2006/0728 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •