vendor:
PEAR
by:
Greg Beaver
5.5
CVSS
MEDIUM
Arbitrary File Overwrite
22
CWE
Product Name: PEAR
Affected Version From: 1
Affected Version To: 1.5.2003
Patch Exists: YES
Related CWE:
CPE: a:pear:pear:1.5.3
Platforms Tested:
2007
Arbitrary File Overwrite in PEAR
Attackers can overwrite arbitrary files by supplying directory-traversal strings through the 'install-as' attribute in an attacker-supplied package.
Mitigation:
Upgrade to PEAR 1.5.4 or higher.