Description
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.
Remediation
References
Related Vulnerabilities
Squid Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-18677)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2014-3981)
Oracle HTTP Server CVE-2020-2952 Vulnerability (CVE-2020-2952)
WordPress Plugin Loginizer SQL Injection (1.6.3)
WordPress Plugin Contact Bank-Contact Form Builder for WordPress Unspecified Vulnerability (2.1.26)