CVE-2017-5630
- EPSS 5.74%
- Published 01.02.2017 23:59:00
- Last modified 20.04.2025 01:37:25
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess ove...
CVE-2011-1072
- EPSS 0.08%
- Published 03.03.2011 01:00:01
- Last modified 11.04.2025 00:51:21
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnera...
CVE-2011-1144
- EPSS 0.12%
- Published 03.03.2011 01:00:01
- Last modified 11.04.2025 00:51:21
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vu...
CVE-2006-0144
- EPSS 1.46%
- Published 09.01.2006 23:03:00
- Last modified 03.04.2025 01:03:51
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malici...
CVE-2005-4154
- EPSS 1.24%
- Published 11.12.2005 02:03:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.