7.5
CVSSv2

CVE-2011-4448

Published: 05/09/2012 Updated: 06/09/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote malicious users to execute arbitrary SQL commands via the default_comment_display parameter in an update action.

Vulnerable Product Search on Vulmon Subscribe to Product

wikkawiki wikkawiki 1.3.1

wikkawiki wikkawiki 1.3.2

Exploits

---------------------------------------------------- WikkaWiki <= 132 Multiple Security Vulnerabilities ---------------------------------------------------- author: Egidio Romano aka EgiX mail: n0b0d13s[at]gmail[dot]com software link: wikkawikiorg/ +--------------------------------- ...
WikkaWiki versions 132 and below suffers from remote SQL injection, unrestricted file upload, arbitrary file download, arbitrary file deletion, remote code execution and cross site request forgery vulnerabilities ...