Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PEAR Base System 安全漏洞
Vulnerability Description
PEAR Base System是PHP Group负责维护的一个PHP扩展及应用的代码仓库。Installer是其中的一个安装包。 PEAR Base System 1.10.1版本中的Installer的download utility class的PECL存在安全漏洞,该漏洞源于在重定向后程序没有验证文件类型和文件名称。攻击者可借助特制的响应利用该漏洞覆盖文件。
CVSS Information
N/A
Vulnerability Type
N/A