CVE Vulnerabilities

CVE-2015-3458

Published: Apr 29, 2015 | Modified: Dec 06, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a template path, which allows remote administrators to include and execute arbitrary PHP files via the phar:// stream wrapper, related to the setScriptPath function. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have privileges to include arbitrary files.

Affected Software

Name Vendor Start Version End Version
Magento Magento 1.9.1.0 (including) 1.9.1.0 (including)
Magento Magento 1.14.1.0 (including) 1.14.1.0 (including)

References