Vulnerability Description
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yiiframework | Yii | >= 2.0.0, < 2.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-devThird Party Advisory
- https://www.yiiframework.com/news/87/yii-2-0-5-is-released-security-fixRelease Notes
- https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-devThird Party Advisory
- https://www.yiiframework.com/news/87/yii-2-0-5-is-released-security-fixRelease Notes
FAQ
What is CVE-2015-5467?
CVE-2015-5467 is a vulnerability with a CVSS score of 9.8 (CRITICAL). web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
How severe is CVE-2015-5467?
CVE-2015-5467 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-5467?
Check the references section above for vendor advisories and patch information. Affected products include: Yiiframework Yii.