PT-2012-1885 · Wikkawiki · Wikkawiki

Published

2012-09-05

·

Updated

2024-08-07

·

CVE-2011-4451

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WikkaWiki versions 1.3.1 through 1.3.2
Description The issue allows remote attackers to write arbitrary PHP code to the spamlog path file via the User-Agent HTTP header in an addcomment request when the spam logging option is enabled. The vendor disputes this issue because the rendering of the spamlog path file never uses the PHP interpreter.
Recommendations For versions 1.3.1 and 1.3.2, consider disabling the spam logging option as a temporary workaround to minimize the risk of exploitation. Restrict access to the spamlog path file to prevent potential abuse. Avoid using the User-Agent HTTP header in addcomment requests until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2011-4451

Affected Products

Wikkawiki