#VU39753 Improper Neutralization of Special Elements in Output Used by a Downstream Component in PEAR - CVE-2017-5630
Published: February 2, 2017 / Updated: August 9, 2020
PEAR
PHP Group
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.