Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVDB-863 and CyVDB-867.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://support.cybozu.com/ja-jp/article/8811 | vendor advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000151 | third party advisory vendor advisory |
http://jvn.jp/en/jp/JVN21025396/index.html | third party advisory vendor advisory |
http://jvn.jp/en/jp/JVN21025396/374951/index.html | vendor advisory |
https://support.cybozu.com/ja-jp/article/8809 | patch vendor advisory |