Description
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-4238 Vulnerability (CVE-2014-4238)
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.1)
Oracle JRE CVE-2013-2461 Vulnerability (CVE-2013-2461)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-39193)
WordPress Plugin Spam Free WordPress Security Bypass (1.9.2)