Remote Code Execution Vulnerability in Yii PHP Framework 1.1.14
CVE-2014-4672

Currently unrated

Key Information:

Vendor
CVE Published:
3 July 2014

What is CVE-2014-4672?

The CDetailView widget in Yii PHP Framework version 1.1.14 is susceptible to a vulnerability that enables remote attackers to execute arbitrary PHP scripts. This flaw can be exploited through specific vectors associated with the value property, potentially allowing unauthorized access to sensitive information and control over the affected system. It is crucial for users of this framework to apply the necessary security updates to mitigate the risk associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-4672 : Remote Code Execution Vulnerability in Yii PHP Framework 1.1.14