Lucene search

K
cvelistMitreCVELIST:CVE-2007-1460
HistoryMar 14, 2007 - 6:00 p.m.

CVE-2007-1460

2007-03-1418:00:00
mitre
www.cve.org
3

7.5 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

7.5 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%