PT-2008-6446 · Wysi Wiki Wyg · Wysi Wiki Wyg
Staker
·
Published
2008-12-03
·
Updated
2017-09-29
·
CVE-2008-5322
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wysi Wiki Wyg version 1.0
Description
The issue allows remote attackers to obtain system information by providing an invalid
categup parameter to the "index.php" endpoint, which in turn calls the phpinfo() function.Recommendations
For Wysi Wiki Wyg version 1.0, consider restricting access to the "index.php" endpoint or disabling the
phpinfo() function call to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wysi Wiki Wyg