Lucene search

K
cveMitreCVE-2011-4449
HistorySep 05, 2012 - 8:55 p.m.

CVE-2011-4449

2012-09-0520:55:01
mitre
web.nvd.nist.gov
15352
cve-2011-4449
wikkawiki
file uploads
remote code execution
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.053

Percentile

93.2%

actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.

Affected configurations

Nvd
Node
wikkawikiwikkawikiMatch1.3.1
OR
wikkawikiwikkawikiMatch1.3.2
VendorProductVersionCPE
wikkawikiwikkawiki1.3.1cpe:2.3:a:wikkawiki:wikkawiki:1.3.1:*:*:*:*:*:*:*
wikkawikiwikkawiki1.3.2cpe:2.3:a:wikkawiki:wikkawiki:1.3.2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.053

Percentile

93.2%