7.5
CVSSv2

CVE-2008-5949

Published: 23/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote malicious users to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5) workspace.php in includes/; and (6) plugins/RSS/files/rss.php.

Vulnerable Product Search on Vulmon Subscribe to Product

tiddlywiki cctiddly 1.7.4

tiddlywiki cctiddly 1.7.6

Exploits

1 ######################################## 1 0 I'm eidelweiss member from Inj3ct0r Team 1 1 ######################################## 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 Developer: tiddlywikiorg/wiki/CcTiddlyDevelo ...
/* $Id: cctiddly-174-rfitxt,v 01 2008/12/04 04:12:20 cOndemned Exp $ ccTiddly 174 (cct_base) Multiple Remote File Inclusion Vulnerabilities found by cOndemned download from : tiddlywikiorg/ccTiddly/ccTiddly_v174zip Probably prior versions are vulnerable too Greetz: ZaBeaTy, str0ke, TBH, Avantura */ 0x01 : file : ...