6.8

CVE-2007-2519

Exploit

Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0.  NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php GroupPear Version1.0
Php GroupPear Version1.0.1
Php GroupPear Version1.1
Php GroupPear Version1.2
Php GroupPear Version1.2.1
Php GroupPear Version1.2b1
Php GroupPear Version1.2b2
Php GroupPear Version1.2b3
Php GroupPear Version1.2b4
Php GroupPear Version1.2b5
Php GroupPear Version1.3
Php GroupPear Version1.3.1
Php GroupPear Version1.3.3
Php GroupPear Version1.3.3.1
Php GroupPear Version1.3.4
Php GroupPear Version1.3.5
Php GroupPear Version1.3.6
Php GroupPear Version1.3b1
Php GroupPear Version1.3b2
Php GroupPear Version1.3b3
Php GroupPear Version1.3b5
Php GroupPear Version1.3b6
Php GroupPear Version1.4.0
Php GroupPear Version1.4.0a1
Php GroupPear Version1.4.0a2
Php GroupPear Version1.4.0a3
Php GroupPear Version1.4.0a4
Php GroupPear Version1.4.0a5
Php GroupPear Version1.4.0a6
Php GroupPear Version1.4.0a7
Php GroupPear Version1.4.0a8
Php GroupPear Version1.4.0a9
Php GroupPear Version1.4.0a10
Php GroupPear Version1.4.0a11
Php GroupPear Version1.4.0a12
Php GroupPear Version1.4.0b1
Php GroupPear Version1.4.0b2
Php GroupPear Version1.4.0rc1
Php GroupPear Version1.4.0rc2
Php GroupPear Version1.4.1
Php GroupPear Version1.4.2
Php GroupPear Version1.4.3
Php GroupPear Version1.4.4
Php GroupPear Version1.4.5
Php GroupPear Version1.4.6
Php GroupPear Version1.4.7
Php GroupPear Version1.4.8
Php GroupPear Version1.4.9
Php GroupPear Version1.4.10
Php GroupPear Version1.4.10rc1
Php GroupPear Version1.4.11
Php GroupPear Version1.5.0
Php GroupPear Version1.5.0a1
Php GroupPear Version1.5.0rc1
Php GroupPear Version1.5.0rc2
Php GroupPear Version1.5.0rc3
Php GroupPear Version1.5.1
Php GroupPear Version1.5.2
Php GroupPear Version1.5.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.38% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P