First published: Fri Oct 07 2011(Updated: )
PHP remote file inclusion vulnerability in dompdf.php
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dompdf/dompdf | >=0.6<0.6.1 | 0.6.2 |
composer/dompdf/dompdf | >=0.6<0.6.1 | 0.6.1 |
Dompdf | =0.6.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4879 has a medium severity rating as it allows remote attackers to execute arbitrary PHP code.
To fix CVE-2010-4879, upgrade to dompdf version 0.6.2 or higher.
CVE-2010-4879 affects dompdf versions prior to 0.6.2, including 0.6.0 beta1 and 0.6.1.
CVE-2010-4879 is a remote file inclusion vulnerability that exploits the 'input_file' parameter in dompdf.php.
Yes, due to the remote execution of arbitrary PHP code, CVE-2010-4879 can potentially lead to a complete system compromise.