Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23595
HistoryApr 10, 2020 - 12:31 a.m.

Directory Traversal

2020-04-1000:31:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.008 Low

EPSS

Percentile

81.7%

php is vulnerable to directory traversal. The vulnerability exists in the PHP’s ZipArchive::extractTo function. If PHP is used to extract a malicious ZIP archive, it could allow an attacker to write arbitrary files anywhere the PHP process has write permissions.

References