PT-2007-6673 · Tikiwiki · Tikiwiki

Publicado

2007-10-26

·

Atualizado

2012-10-24

·

CVE-2007-5682

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TikiWiki versions prior to 1.9.8.2
Description The issue allows remote attackers to execute arbitrary code by utilizing variable functions and variable variables to write variables whose names match the whitelist. This is due to an incomplete blacklist vulnerability in the tiki-graph formula.php file.
Recommendations For versions prior to 1.9.8.2, update to version 1.9.8.2 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5682

Produtos afetados

Tikiwiki