The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

is ziparchive secure

Discussion in 'Security' started by yamaharr1, Jul 24, 2013.

  1. yamaharr1

    yamaharr1 Well-Known Member

    Joined:
    Jun 22, 2007
    Messages:
    91
    Likes Received:
    0
    Trophy Points:
    6
    I've been doing lots of reading but haven't found anything up to date, is ziparchive secure?

    The last thing I've found was in 2012 and showed it to be a security risk, is this still the case or has it all been sorted?
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    Could you clarify the specific application you are referring to, and what method you are using to install it? For instance, is this the ZipArchive PHP class?

    Thank you.
     
  3. yamaharr1

    yamaharr1 Well-Known Member

    Joined:
    Jun 22, 2007
    Messages:
    91
    Likes Received:
    0
    Trophy Points:
    6
    Hello

    Yes the PHP ZipArchive,

    I haven't looked into the install method if it is available as a module then that way otherwise whichever is available.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    You can select "Zip" as a PHP module under the "Exhaustive Options List" for PHP. I am not aware of any specific security concerns regarding this module, but feel free to reference a specific security report and we can investigate that for you.

    Thank you.
     
  5. yamaharr1

    yamaharr1 Well-Known Member

    Joined:
    Jun 22, 2007
    Messages:
    91
    Likes Received:
    0
    Trophy Points:
    6
    There was a security risk with relative paths in 2009 that was supposedly fixed but it seemed to pop back up in 2012 I can't find any information in regards to it being secure or insecure now.

    I will have to guess that if it was insecure there would be more information out in posts, if you do come across anything that would be great, thank you.
     
Loading...

Share This Page