CVSS Summary
Score | 8 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Complete |
Integrity | Partial |
Availability | Partial |
Last revised:
Administrators can perform Local File include attacks, which is a privilege escalation on systems where the administrator doesn’t have control over the server.
If administrators can upload PHP files (or any file which can contain “<?php …”), they can also perform arbitrary code execution by the same method.
Current state: Fixed
Score | 8 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Complete |
Integrity | Partial |
Availability | Partial |
2013-08-07: Discovered
2015-07-13: Reported to vendor by email
2015-07-13: Requested CVE
2015-07-14: Vendor responded confirming fixed in version 2.3
2015-07-14: Published
Upgrade to version 2.3 or later