7.5
CVSSv2

CVE-2014-6289

Published: 03/10/2014 Updated: 06/10/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension prior to 3.0.1 and Tools for Extbase development (pt_extbase) extension prior to 1.5.1 allows remote malicious users to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

daniel lienert yet another gallery

michael knoll tools for extbase developmen