CyberSec.Space Logo
Back to CVE Browser

CVE-2007-1460

MEDIUM
5.0
CVSS Severity Score
EPSS Score0.0340%
EPSS Percentile37.89th
PublishedMar 14, 2007
Last ModifiedApr 23, 2026

Vulnerability Description

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

Affected Platforms (CPE)

πŸ“¦
Php

Php

<= 4.4.6
πŸ“¦
Php

Php

= 1.0
πŸ“¦
Php

Php

= 2.0
πŸ“¦
Php

Php

= 2.0b10
πŸ“¦
Php

Php

= 3.0
πŸ“¦
Php

Php

= 3.0.1
πŸ“¦
Php

Php

= 3.0.2
πŸ“¦
Php

Php

= 3.0.3
πŸ“¦
Php

Php

= 3.0.4
πŸ“¦
Php

Php

= 3.0.5
πŸ“¦
Php

Php

= 3.0.6
πŸ“¦
Php

Php

= 3.0.7
πŸ“¦
Php

Php

= 3.0.8
πŸ“¦
Php

Php

= 3.0.9
πŸ“¦
Php

Php

= 3.0.10
πŸ“¦
Php

Php

= 3.0.11
πŸ“¦
Php

Php

= 3.0.12
πŸ“¦
Php

Php

= 3.0.13
πŸ“¦
Php

Php

= 3.0.14
πŸ“¦
Php

Php

= 3.0.15
πŸ“¦
Php

Php

= 3.0.16
πŸ“¦
Php

Php

= 3.0.17
πŸ“¦
Php

Php

= 3.0.18
πŸ“¦
Php

Php

= 4.0
πŸ“¦
Php

Php

= 4.0
πŸ“¦
Php

Php

= 4.0
πŸ“¦
Php

Php

= 4.0
πŸ“¦
Php

Php

= 4.0
πŸ“¦
Php

Php

= 4.0.0
πŸ“¦
Php

Php

= 4.0.1
πŸ“¦
Php

Php

= 4.0.2
πŸ“¦
Php

Php

= 4.0.3
πŸ“¦
Php

Php

= 4.0.4
πŸ“¦
Php

Php

= 4.0.5
πŸ“¦
Php

Php

= 4.0.6
πŸ“¦
Php

Php

= 4.0.7
πŸ“¦
Php

Php

= 4.1.0
πŸ“¦
Php

Php

= 4.1.1
πŸ“¦
Php

Php

= 4.1.2
πŸ“¦
Php

Php

= 4.2.0
πŸ“¦
Php

Php

= 4.2.1
πŸ“¦
Php

Php

= 4.2.2
πŸ“¦
Php

Php

= 4.2.3
πŸ“¦
Php

Php

= 4.3.0
πŸ“¦
Php

Php

= 4.3.1
πŸ“¦
Php

Php

= 4.3.2
πŸ“¦
Php

Php

= 4.3.3
πŸ“¦
Php

Php

= 4.3.4
πŸ“¦
Php

Php

= 4.3.5
πŸ“¦
Php

Php

= 4.3.6
πŸ“¦
Php

Php

= 4.3.7
πŸ“¦
Php

Php

= 4.3.8
πŸ“¦
Php

Php

= 4.3.9
πŸ“¦
Php

Php

= 4.3.10
πŸ“¦
Php

Php

= 4.3.11
πŸ“¦
Php

Php

= 4.4.0
πŸ“¦
Php

Php

= 4.4.1
πŸ“¦
Php

Php

= 4.4.2
πŸ“¦
Php

Php

= 4.4.3
πŸ“¦
Php

Php

= 4.4.4
πŸ“¦
Php

Php

= 4.4.5
πŸ“¦
Php

Php

= 5.2.0
πŸ“¦
Php

Php

= 5.2.1

References & Advisories

Related Vulnerabilities