PHP Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2014-9767 - Vulnerability Database

PHP Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2014-9767

Medium
Reference: CVE-2014-9767
Title: PHP Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45 5.5.x before 5.5.29 and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive.