Description
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.
Remediation
References
Related Vulnerabilities
WordPress Plugin Uji Countdown Cross-Site Scripting (2.0.6)
Django Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-23833)
GlassFish CVE-2016-5477 Vulnerability (CVE-2016-5477)
IBM WebSEAL Missing Authorization Vulnerability (CVE-2019-4158)
WordPress Plugin Images Lazyload and Slideshow Cross-Site Scripting (3.2)