Input passed via keys of the $_POST array to translate.php (when "mode" is set to "save") is not properly sanitized before being stored in a file into 'i18n' directory with a .php extension. This could allow authenticated users to inject and execute arbitrary PHP code.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Authentication Required,
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a fix in the SVN trunk to address this vulnerability. The vendor has stated that a fix will be included in version 3.66 when it is released.