7.5
CVE-2002-2106
- EPSS 2.69%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wikkitikkitavi ≫ Wikkitikkitavi Version0.5
Wikkitikkitavi ≫ Wikkitikkitavi Version0.10
Wikkitikkitavi ≫ Wikkitikkitavi Version0.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.69% | 0.84 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://securitytracker.com/id?1003307
http://sourceforge.net/mailarchive/message.php?msg_id=185752
http://www.securityfocus.com/bid/3946
https://exchange.xforce.ibmcloud.com/vulnerabilities/8001