6.4
CVSSv2

CVE-2011-4450

Published: 05/09/2012 Updated: 13/09/2012
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote malicious users to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.

Vulnerable Product Search on Vulmon Subscribe to Product

wikkawiki wikkawiki 1.3.1

wikkawiki wikkawiki 1.3.2

Exploits

---------------------------------------------------- WikkaWiki <= 132 Multiple Security Vulnerabilities ---------------------------------------------------- author: Egidio Romano aka EgiX mail: n0b0d13s[at]gmail[dot]com software link: wikkawikiorg/ +--------------------------------- ...
WikkaWiki versions 132 and below suffers from remote SQL injection, unrestricted file upload, arbitrary file download, arbitrary file deletion, remote code execution and cross site request forgery vulnerabilities ...