RSS   Vulnerabilities for 'PEAR'   RSS

2017-02-01
 
CVE-2017-5630

CWE-74
 

 
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

 
2009-11-29
 
CVE-2009-4025

CWE-78
 

 
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.

 
 
CVE-2009-4024

CWE-94
 

 
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.

 
 
CVE-2009-4023

CWE-94
 

 
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.

 

 >>> Vendor: PEAR 10 Products
Xml rpc
MAIL
PEAR
Text password
Pear liveuser
Pear archive tar
Pear archive zip
Structures datagrid datasource mdb2
Html ajax
Crypt gpg


Copyright 2024, cxsecurity.com

 

Back to Top