CVSS Summary
| Score | 8 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Complete |
| Integrity | Partial |
| Availability | Partial |
Last revised:
Administrators can perform Local File include attacks, which is a privilege escalation on systems where the administrator doesn’t have control over the server.
If administrators can upload PHP files (or any file which can contain “<?php …”), they can also perform arbitrary code execution by the same method.
Current state: Fixed
| Score | 8 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Complete |
| Integrity | Partial |
| Availability | Partial |
2013-08-07: Discovered
2015-07-13: Reported to vendor by email
2015-07-13: Requested CVE
2015-07-14: Vendor responded confirming fixed in version 2.3
2015-07-14: Published
Upgrade to version 2.3 or later