PEAR core file overwrite vulnerability
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 7, 2023
Description
Published by the National Vulnerability Database
Feb 1, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 7, 2023
Last updated
Jul 7, 2023
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
References