Overview
Older versions of PHPCow contain a file inclusion vulnerability that could allow an attacker to take control of a vulnerable application.
Description
PHPCow is a content management system that uses PHP. Older versions of PHP contain a file inclusion vulnerability. We are aware of reports that this issue being actively exploited. |
Impact
A remote attacker may be able to take control of a vulnerable PHPCow application. |
Solution
Upgrade It is not clear which versions of PHPCow are vulnerable. The PHPCow suppport team has reported that recent versions of PHPCow addressed this issue. Contact PHPCow for more information about obtaining updated software. |
Workarounds for users
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 1.35 |
Date Public: | 2008-11-19 |
Date First Published: | 2008-11-19 |
Date Last Updated: | 2008-11-19 16:35 UTC |
Document Revision: | 27 |