Description
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.
Remediation
References
Related Vulnerabilities
Liferay Portal Insufficient Session Expiration Vulnerability (CVE-2021-33322)
MySQL CVE-2021-2154 Vulnerability (CVE-2021-2154)
WebLogic CVE-2023-21841 Vulnerability (CVE-2023-21841)
Moodle Improper Authentication Vulnerability (CVE-2013-2245)
Varnish Cache Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0345)