6.8
CVSSv2

CVE-2011-4452

Published: 05/09/2012 Updated: 06/09/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote malicious users to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete operation, as demonstrated by an {{image}} action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wikkawiki wikkawiki 1.3.2

wikkawiki wikkawiki 1.3.1

Exploits

---------------------------------------------------- WikkaWiki <= 132 Multiple Security Vulnerabilities ---------------------------------------------------- author: Egidio Romano aka EgiX mail: n0b0d13s[at]gmail[dot]com software link: wikkawikiorg/ +--------------------------------- ...
WikkaWiki versions 132 and below suffers from remote SQL injection, unrestricted file upload, arbitrary file download, arbitrary file deletion, remote code execution and cross site request forgery vulnerabilities ...