PHP ZipArchive::extractTo()函数.zip文件目录遍历漏洞

来源:互联网 发布:windowsxp仿mac桌面 编辑:程序博客网 时间:2024/05/17 02:52

PHP is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input.


A successful attack may allow an attacker to create or overwrite arbitrary files on the system. This may allow arbitrary script code to run in the context of the webserver.

PHP 5.2.6 and prior versions are vulnerable.

../../../../../../../../../../../var/www/wr_dir/evil.php

 

原创粉丝点击