vendor:
TikiWiki
by:
Matteo Cantoni, jduck
7.5
CVSS
HIGH
Remote PHP Code Execution
CWE
Product Name: TikiWiki
Affected Version From: 1.9.2008
Affected Version To: 1.9.2008
Patch Exists: NO
Related CWE: CVE-2007-5423
CPE: a:tikiwiki:tikiwiki:1.9.8
Platforms Tested: php
2007
TikiWiki tiki-graph_formula Remote PHP Code Execution
TikiWiki (<= 1.9.8) contains a flaw that may allow a remote attacker to execute arbitrary PHP code. The issue is due to 'tiki-graph_formula.php' script not properly sanitizing user input supplied to create_function(), which may allow a remote attacker to execute arbitrary PHP code resulting in a loss of integrity.
Mitigation:
Update to the latest version of TikiWiki.