Description
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2005-0524)
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3055)
Microsoft SQL Server CVE-2023-32028 Vulnerability (CVE-2023-32028)
WordPress Plugin Floating Social Bar Cross-Site Scripting (1.1.6)
Ruby on Rails Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-5419)