Vulnerabilities > CVE-2006-7049 - Unspecified vulnerability in Wikkawiki 1.1.6.0/1.1.6.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN wikkawiki
nessus
Summary
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | CGI abuses |
NASL id | WIKKA_METHOD_NAME_INFO_DISCLOSURE.NASL |
description | The remote host is running Wikka, a lightweight, open source wiki application written in PHP. The version of Wikka installed on the remote host has a programming error in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21729 |
published | 2006-06-17 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21729 |
title | Wikka wikka.php Local File Inclusion |
code |
|
References
- http://secunia.com/advisories/20628
- http://wikkawiki.org/WikkaReleaseNotes
- http://www.osvdb.org/26543
- http://www.securityfocus.com/bid/18484
- http://www.vupen.com/english/advisories/2006/2381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27226
- http://secunia.com/advisories/20628
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27226
- http://www.vupen.com/english/advisories/2006/2381
- http://www.securityfocus.com/bid/18484
- http://www.osvdb.org/26543
- http://wikkawiki.org/WikkaReleaseNotes