Directory traversal vulnerability in Zend Platform 2.2.1 and previous versions allows remote malicious users to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identifier (PHPSESSID). NOTE: in some cases, this issue can be leveraged to perform direct static code injection.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zend zend platform |