See how jason orcutt compares to other vendors in security performance
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUSLIBRARYBASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test.php scripts.