PHP versions 5.2.6 and below suffer from a directory traversal vulnerability in ZipArchive::extractTo().