First published: Mon Jun 30 2014(Updated: )
The CDetailView widget allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/yiisoft/yii | >=1.1.14<1.1.15 | |
Yiiframework Yiiframework | =1.1.14 | |
composer/yiisoft/yii | >=1.1.14<1.1.15 | 1.1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4672 is considered a critical vulnerability due to its ability to allow remote code execution on affected systems.
To fix CVE-2014-4672, upgrade the Yii PHP Framework to version 1.1.15 or later.
CVE-2014-4672 affects Yii Framework version 1.1.14 and all versions up to, but not including, 1.1.15.
CVE-2014-4672 can be exploited by remote attackers to execute arbitrary PHP scripts on the server.
Yes, CVE-2014-4672 was publicly disclosed and has known exploits that target vulnerable versions of Yii.