Michiel Rook

2 exploits Active since Jan 2021
CVE-2020-36193 WRITEUP HIGH WRITEUP
PHP Archive Tar < 1.4.11 - Path Traversal
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVSS 7.5
CVE-2021-32610 WRITEUP HIGH WRITEUP
PHP Archive Tar < 1.4.14 - Symlink Following
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVSS 7.1