PT-2007-6673 · Tikiwiki · Tikiwiki

Published

2007-10-26

·

Updated

2012-10-24

·

CVE-2007-5682

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TikiWiki versions prior to 1.9.8.2
Description The issue allows remote attackers to execute arbitrary code by utilizing variable functions and variable variables to write variables whose names match the whitelist. This is due to an incomplete blacklist vulnerability in the tiki-graph formula.php file.
Recommendations For versions prior to 1.9.8.2, update to version 1.9.8.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5682

Affected Products

Tikiwiki