Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP Pear‘/tmp/’Directory 安全漏洞
Vulnerability Description
PHP PEAR(全称PHP Extension and Application Repository)是PHP Group负责维护的一个PHP扩展及应用的代码仓库。 PHP 5.6.0及之前版本的PEAR中REST.php脚本中的‘retrieveCacheFirst’和‘useLocalCache’函数中的‘PEAR_REST’类中存在安全漏洞。本地攻击者可通过在/tmp/pear/cache/ URL下的rest.cachefile或rest.cacheid文件上实施符号链接攻击利用该漏洞写入任意文
CVSS Information
N/A
Vulnerability Type
N/A