An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying computer; other attacks are also possible.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.