7.5
CVSSv3

CVE-2015-6833

Published: 19/01/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the PharData class in PHP prior to 5.4.44, 5.5.x prior to 5.5.28, and 5.6.x prior to 5.6.12 allows remote malicious users to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.6.1

php php 5.5.0

php php 5.6.0

php php 5.6.5

php php 5.5.19

php php

php php 5.5.25

php php 5.5.1

php php 5.5.5

php php 5.6.4

php php 5.5.21

php php 5.6.6

php php 5.5.14

php php 5.5.7

php php 5.6.11

php php 5.6.2

php php 5.6.10

php php 5.5.12

php php 5.5.6

php php 5.6.7

php php 5.5.3

php php 5.5.23

php php 5.5.8

php php 5.5.27

php php 5.5.24

php php 5.5.11

php php 5.5.13

php php 5.5.4

php php 5.5.26

php php 5.6.9

php php 5.5.10

php php 5.6.3

php php 5.5.22

php php 5.6.8

php php 5.5.18

php php 5.5.20

php php 5.5.2

php php 5.5.9

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in the PHP language: CVE-2015-4598 thoger at redhat dot com discovered that paths containing a NUL character were improperly handled, thus allowing an attacker to manipulate unexpected files on the server CVE-2015-4643 Max Spelsberg discovered an integer overflow flaw leading to a ...
A flaw was found in the way the way PHP's Phar extension parsed Phar archives A specially crafted archive could cause PHP to crash or, possibly, execute arbitrary code when opened ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...