| [Japanese] | 
| JVNDB-2015-000151 | 
| Multiple PHP code execution vulnerabilitles in Cybozu Garoon | 
|
| 
 
Cybozu Garoon is a groupware. Cybozu Garoon contains multiple PHP code execution vulnerabilities.
 * [CyVDB-863] Cybozu Garoon allows remote authenticated users to execute arbitrary PHP code, [CyVDB-867] Cybozu Garoon allows remote authenticated users to execute arbitrary PHP code (CVE-2015-5646)
 * [CyVDB-866] Cybozu Garoon allows remote authenticated users to execute arbitrary PHP code in RSS Reader function (CVE-2015-5647)
 
 For more details, refer to the information provided by the developer.
 | 
|
| 
 
  CVSS V2 Severity:Base Metrics 8.5 (High) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: MediumAuthentication: Single InstanceConfidentiality Impact: CompleteIntegrity Impact: CompleteAvailability Impact: Complete 
  
 | 
|
| 
 
	
 | 
| 
 
	Cybozu, Inc.
	
		Cybozu Garoon 3.0.0 to 4.0.3 | 
| 
 
	
 | 
|
| 
 
An authenticated attacker may execute arbitrary PHP code on the application server.
 | 
|
| 
 
[Apply the Patch]Apply the appropriate patch according to the information provided by the developer.
 
 [Added on May 30, 2016]
 [Update the Software]
 The developer has released the version that contains a fix for this vulnerability.
 Update to the latest version according to the information provided by the developer.
 | 
|
| 
 
	Cybozu, Inc.
	
 | 
|
| 
 
	Code Injection(CWE-94) [IPA Evaluation] | 
|
| 
 
	CVE-2015-5646 CVE-2015-5647  | 
|
| 
 
	JVN : JVN#21025396 National Vulnerability Database (NVD) : CVE-2015-5646 National Vulnerability Database (NVD) : CVE-2015-5647 IPA SECURITY ALERTS : Security Alert for Vulnerability in Cybozu Garoon (JVN#21025396) (in Japanese) | 
|
| 
 
	[2015/10/07]Web page was published
 [2015/10/14]
 References : Contents were added
 [2016/05/30]
 Solution was modified
 
 |