7.5
CVE-2006-7049
- EPSS 1.6%
- Veröffentlicht 24.02.2007 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:34:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.6% | 0.727 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20628
http://wikkawiki.org/WikkaReleaseNotes
http://www.osvdb.org/26543
http://www.securityfocus.com/bid/18484
http://www.vupen.com/english/advisories/2006/2381
https://exchange.xforce.ibmcloud.com/vulnerabilities/27226