CVE-2010-4879: Code Injection
Published Oct 7, 2011
·Updated
PHP remote file inclusion vulnerability in dompdf.php
Affected Software
3 affected componentsFixes available
composer/dompdf/dompdf>=0.6, <0.6.1
0.6.2
composer/dompdf/dompdf>=0.6<0.6.1
0.6.1
Digitaljunkies Dompdf=0.6.0-beta1
Event History
Oct 7, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Mar 10, 2014
Advisory Published
09:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2010-4879?
CVE-2010-4879 has a medium severity rating as it allows remote attackers to execute arbitrary PHP code.
2
How do I fix CVE-2010-4879?
To fix CVE-2010-4879, upgrade to dompdf version 0.6.2 or higher.
3
What software is affected by CVE-2010-4879?
CVE-2010-4879 affects dompdf versions prior to 0.6.2, including 0.6.0 beta1 and 0.6.1.
4
What is the nature of the vulnerability in CVE-2010-4879?
CVE-2010-4879 is a remote file inclusion vulnerability that exploits the 'input_file' parameter in dompdf.php.
5
Can CVE-2010-4879 lead to a complete system compromise?
Yes, due to the remote execution of arbitrary PHP code, CVE-2010-4879 can potentially lead to a complete system compromise.