An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, and obtain sensitive information.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.
Disclosure Timeline:
Initial Release : Jun 03 2012