CVE-2017-5630: PHP PEAR
High severity, CVSS 7.5. EPSS: 12.5% chance of exploitation in the next 30 days.
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
Affected products
- PHP PEAR: version 1.10.1 only
Published 2017-02-01. Last modified 2026-06-17.