vendor:
TikiWiki
by:
ShAnKaR
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: TikiWiki
Affected Version From: 1
Affected Version To: 1.9.2008
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
TikiWiki <= 1.9.8 Remote Command Execution Exploit
TikiWiki contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'tiki-graph_formula.php' script not properly sanitizing user input supplied to the f variable, which may allow a remote attacker to execute arbitrary PHP commands resulting in a loss of integrity.
Mitigation:
Apply a patch or update to a version of TikiWiki that is not affected by this vulnerability. Sanitize user input to prevent command injection.