Vulnerabilities > Wikkawiki > Wikkawiki > 1.1.6.0

DATE CVE VULNERABILITY TITLE RISK
2013-09-25 CVE-2013-5586 Cross-Site Scripting vulnerability in Wikkawiki
Cross-site scripting (XSS) vulnerability in wikka.php in WikkaWiki before 1.3.4-p1 allows remote attackers to inject arbitrary web script or HTML via the wakka parameter to sql/.
network
wikkawiki CWE-79
4.3
2007-05-09 CVE-2007-2552 Information Exposure vulnerability in Wikkawiki
The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds.
network
low complexity
wikkawiki CWE-200
5.0
2007-02-24 CVE-2006-7049 Information Disclosure vulnerability in Wikkawiki Method Function
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
network
low complexity
wikkawiki
7.5