First published: Wed Dec 16 2015(Updated: )
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitrix | <=1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8358 has a medium severity rating due to its potential to allow remote file inclusion.
To fix CVE-2015-8358, upgrade the bitrix.mpbuilder module to version 1.0.12 or later.
CVE-2015-8358 affects versions of the bitrix.mpbuilder module prior to 1.0.12.
Yes, CVE-2015-8358 can be exploited remotely by an attacker with administrative access.
CVE-2015-8358 is associated with directory traversal attacks that can lead to local file inclusion.