Vulnerabilities > CVE-2002-2106 - Remote File Include vulnerability in Wikkitikkitavi 0.10/0.20/0.5

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
wikkitikkitavi
exploit available

Summary

PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.

Exploit-Db

descriptionWikkiTikkiTavi 0.x Remote File Include Vulnerability. CVE-2002-2106. Webapps exploit for php platform
idEDB-ID:21241
last seen2016-02-02
modified2002-01-02
published2002-01-02
reporterScott Moonen
sourcehttps://www.exploit-db.com/download/21241/
titleWikkiTikkiTavi 0.x - Remote File Include Vulnerability