« Volver al listado

PHP

PHP Archive TAR: vulnerabilidades y CVE

PHP Archive TAR tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses0
Críticas0
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-28949Alta (7.8)85%⚠ Explotación activa19 nov 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2020-36193Alta (7.5)71%⚠ Explotación activa18 ene 2021
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-32610Alta (7.1)73%—30 jul 2021
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVE-2020-36193Alta (7.5)71%⚠ Explotación activa18 ene 2021
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVE-2020-28949Alta (7.8)85%⚠ Explotación activa19 nov 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2020-28948Alta (7.8)47%—19 nov 2020
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1565.001 Stored Data Manipulation2
  2. T1190 Exploit Public-Facing Application1
  3. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de PHP