pear Vulnerabilities and Affected Products
Vulnerabilities associated with Archive_Tar.
Products
Clear product- pearweb9 vulnerabilities
- Archive_Tar2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36193HIGH | Directory Traversal in Archive_TarTar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. | CVSS7.5v3.1 | EPSS70.6% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-28949HIGH | Multiple vulnerabilities through filename manipulation in Archive_TarArchive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. CWE-74Nov 19, 2020 | CVSS7.8v3.1 | EPSS84.6% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |