Vulnerabilities > CVE-2011-4449 - Unspecified vulnerability in Wikkawiki 1.3.1/1.3.2

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
wikkawiki
exploit available

Summary

actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.

Vulnerable Configurations

Part Description Count
Application
Wikkawiki
2

Exploit-Db

  • descriptionWikkaWiki 1.3.2 Spam Logging PHP Injection. CVE-2011-4449. Webapps exploit for php platform
    idEDB-ID:18865
    last seen2016-02-02
    modified2012-05-12
    published2012-05-12
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/18865/
    titleWikkaWiki 1.3.2 Spam Logging PHP Injection
  • descriptionWikkaWiki <= 1.3.2 - Multiple Security Vulnerabilities. CVE-2011-4448,CVE-2011-4449,CVE-2011-4450,CVE-2011-4451,CVE-2011-4452. Webapps exploit for php pla...
    idEDB-ID:18177
    last seen2016-02-02
    modified2011-11-30
    published2011-11-30
    reporterEgiX
    sourcehttps://www.exploit-db.com/download/18177/
    titleWikkaWiki <= 1.3.2 - Multiple Security Vulnerabilities

Packetstorm

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:24270
    last seen2017-11-19
    modified2011-12-01
    published2011-12-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-24270
    titleWikkaWiki &lt;= 1.3.2 Multiple Security Vulnerabilities
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:72373
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-72373
    titleWikkaWiki <= 1.3.2 - Multiple Security Vulnerabilities