6.8
CVSSv2

CVE-2008-1170

Published: 05/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote malicious users to execute arbitrary PHP code via a URL in the page parameter to (1) minimal/wiki.php and (2) simplest/wiki.php.

Vulnerable Product Search on Vulmon Subscribe to Product

kcwiki kcwiki 1.0

Exploits

source: wwwsecurityfocuscom/bid/28074/info KC Wiki is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process This may allow ...
source: wwwsecurityfocuscom/bid/28074/info KC Wiki is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process This may allo ...