Description
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
Remediation
References
Related Vulnerabilities
PrestaShop Incorrect Authorization Vulnerability (CVE-2020-5288)
WordPress Plugin Clipboard Images Arbitrary File Upload (0.3)
WordPress Plugin Role Scoper Cross-Site Scripting (1.3.64)
MySQL CVE-2015-0438 Vulnerability (CVE-2015-0438)
WordPress Plugin Simple Photo Gallery Cross-Site Scripting (1.8.0)