Lucene search

K

Phpwiki Security Vulnerabilities

cve
cve

CVE-2017-7981

Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this.....

8.8CVSS

8.8AI Score

0.015EPSS

2017-04-29 04:59 PM
30
cve
cve

CVE-2014-5519

The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party...

7.8AI Score

0.949EPSS

2014-09-11 02:16 PM
27
cve
cve

CVE-2007-3193

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP...

6.5AI Score

0.028EPSS

2007-06-12 11:30 PM
23
cve
cve

CVE-2007-2025

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP...

6.5AI Score

0.019EPSS

2007-04-13 06:19 PM
26
cve
cve

CVE-2007-2024

Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5...

6.5AI Score

0.034EPSS

2007-04-13 06:19 PM
27