CVE-2015-8358: Path Traversal
Published Dec 16, 2015
·Updated
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilderstep2.php.
Affected Software
1 affected component
Bitrix Mpbuilder Bitrix<=1.0.11
Event History
Dec 16, 2015
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8358?
CVE-2015-8358 has a medium severity rating due to its potential to allow remote file inclusion.
2
How do I fix CVE-2015-8358?
To fix CVE-2015-8358, upgrade the bitrix.mpbuilder module to version 1.0.12 or later.
3
What systems are affected by CVE-2015-8358?
CVE-2015-8358 affects versions of the bitrix.mpbuilder module prior to 1.0.12.
4
Can CVE-2015-8358 be exploited remotely?
Yes, CVE-2015-8358 can be exploited remotely by an attacker with administrative access.
5
What kind of attack is associated with CVE-2015-8358?
CVE-2015-8358 is associated with directory traversal attacks that can lead to local file inclusion.