AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-2519

MEDIUM · CVSS 6.8 EPSS 7.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-05-22 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-2519
Severity
MEDIUM
CVSS
6.8
EPSS
7.29%

Original Filing — NVD Description

Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.