info
discussion
exploit
solution
references
PHP ZipArchive::extractTo() '.zip' Files Directory Traversal Vulnerability
References:
PHP Homepage
(PHP)
PHP ZipArchive::extractTo() Directory Traversal Vulnerability
(SektionEins GmbH)
Advisory 06/2008: PHP ZipArchive::extractTo() Directory Traversal Vulnerability
(Stefan Esser
)
Privacy Statement
Copyright 2010, SecurityFocus