CVE-2015-5467: class yii\web\ViewAction allowed to include arbitrary files that end with .php

Severity: Critical

CVSS Score: 9.8

web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.