Total vulnerabilities in the database
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
Software | From | Fixed in |
---|---|---|
apereo / phpcas | 0.2 | 0.2.x |
apereo / phpcas | 0.3 | 0.3.x |
apereo / phpcas | 0.3.1 | 0.3.1.x |
apereo / phpcas | 0.3.2 | 0.3.2.x |
apereo / phpcas | 0.4 | 0.4.x |
apereo / phpcas | 0.4.1 | 0.4.1.x |
apereo / phpcas | 0.4.8 | 0.4.8.x |
apereo / phpcas | 0.4.9 | 0.4.9.x |
apereo / phpcas | 0.4.10 | 0.4.10.x |
apereo / phpcas | 0.4.11 | 0.4.11.x |
apereo / phpcas | 0.4.12 | 0.4.12.x |
apereo / phpcas | 0.4.13 | 0.4.13.x |
apereo / phpcas | 0.4.14 | 0.4.14.x |
apereo / phpcas | 0.4.15 | 0.4.15.x |
apereo / phpcas | 0.4.16 | 0.4.16.x |
apereo / phpcas | 0.4.17 | 0.4.17.x |
apereo / phpcas | 0.4.18 | 0.4.18.x |
apereo / phpcas | 0.4.19 | 0.4.19.x |
apereo / phpcas | 0.4.20 | 0.4.20.x |
apereo / phpcas | 0.4.21 | 0.4.21.x |
apereo / phpcas | 0.4.22 | 0.4.22.x |
apereo / phpcas | 0.4.23 | 0.4.23.x |
apereo / phpcas | 0.5.0 | 0.5.0.x |
apereo / phpcas | 0.5.1 | 0.5.1.x |
apereo / phpcas | 0.6.0 | 0.6.0.x |
apereo / phpcas | 1.0.0 | 1.0.0.x |
apereo / phpcas | 1.0.1 | 1.0.1.x |
apereo / phpcas | 1.1.0 | 1.1.0.x |
apereo / phpcas | 1.1.1 | 1.1.1.x |
apereo / phpcas | - | 1.1.2.x |