AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5658

HIGH · CVSS 7.5 EPSS 4.03%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-5658
Severity
HIGH
CVSS
7.5
EPSS
4.03%

Original NVD Description

Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.