Security Advisory

CVE-2006-0144

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-01-09 23:00:00
Last updated 2024-08-07 16:25:33
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.