Lucene search

K
prionPRIOn knowledge basePRION:CVE-2011-4451
HistorySep 05, 2012 - 8:55 p.m.

Design/Logic Flaw

2012-09-0520:55:00
PRIOn knowledge base
www.prio-n.com
8

7.5 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.6%

DISPUTED libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter.

CPENameOperatorVersion
wikkawikieq1.3.2
wikkawikieq1.3.1

7.5 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.6%