7.5

CVE-2011-4453

Exploit
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PmwikiPmwiki Version2.0.0
PmwikiPmwiki Version2.0.1
PmwikiPmwiki Version2.0.2
PmwikiPmwiki Version2.0.3
PmwikiPmwiki Version2.0.4
PmwikiPmwiki Version2.0.5
PmwikiPmwiki Version2.0.6
PmwikiPmwiki Version2.0.7
PmwikiPmwiki Version2.0.8
PmwikiPmwiki Version2.0.9
PmwikiPmwiki Version2.0.10
PmwikiPmwiki Version2.0.11
PmwikiPmwiki Version2.0.12
PmwikiPmwiki Version2.0.13
PmwikiPmwiki Version2.1.0
PmwikiPmwiki Version2.1.1
PmwikiPmwiki Version2.1.2
PmwikiPmwiki Version2.1.3
PmwikiPmwiki Version2.1.4
PmwikiPmwiki Version2.1.5
PmwikiPmwiki Version2.1.6
PmwikiPmwiki Version2.1.7
PmwikiPmwiki Version2.1.8
PmwikiPmwiki Version2.1.9
PmwikiPmwiki Version2.1.10
PmwikiPmwiki Version2.1.11
PmwikiPmwiki Version2.1.12
PmwikiPmwiki Version2.1.13
PmwikiPmwiki Version2.1.14
PmwikiPmwiki Version2.1.15
PmwikiPmwiki Version2.1.16
PmwikiPmwiki Version2.1.17
PmwikiPmwiki Version2.1.18
PmwikiPmwiki Version2.1.19
PmwikiPmwiki Version2.1.20
PmwikiPmwiki Version2.1.21
PmwikiPmwiki Version2.1.22
PmwikiPmwiki Version2.1.23
PmwikiPmwiki Version2.1.24
PmwikiPmwiki Version2.1.25
PmwikiPmwiki Version2.1.26
PmwikiPmwiki Version2.1.27
PmwikiPmwiki Version2.2.0
PmwikiPmwiki Version2.2.0 Updatebeta1
PmwikiPmwiki Version2.2.0 Updatebeta10
PmwikiPmwiki Version2.2.0 Updatebeta11
PmwikiPmwiki Version2.2.0 Updatebeta12
PmwikiPmwiki Version2.2.0 Updatebeta13
PmwikiPmwiki Version2.2.0 Updatebeta14
PmwikiPmwiki Version2.2.0 Updatebeta15
PmwikiPmwiki Version2.2.0 Updatebeta16
PmwikiPmwiki Version2.2.0 Updatebeta17
PmwikiPmwiki Version2.2.0 Updatebeta18
PmwikiPmwiki Version2.2.0 Updatebeta19
PmwikiPmwiki Version2.2.0 Updatebeta2
PmwikiPmwiki Version2.2.0 Updatebeta20
PmwikiPmwiki Version2.2.0 Updatebeta21
PmwikiPmwiki Version2.2.0 Updatebeta22
PmwikiPmwiki Version2.2.0 Updatebeta23
PmwikiPmwiki Version2.2.0 Updatebeta24
PmwikiPmwiki Version2.2.0 Updatebeta25
PmwikiPmwiki Version2.2.0 Updatebeta26
PmwikiPmwiki Version2.2.0 Updatebeta27
PmwikiPmwiki Version2.2.0 Updatebeta28
PmwikiPmwiki Version2.2.0 Updatebeta29
PmwikiPmwiki Version2.2.0 Updatebeta3
PmwikiPmwiki Version2.2.0 Updatebeta30
PmwikiPmwiki Version2.2.0 Updatebeta31
PmwikiPmwiki Version2.2.0 Updatebeta32
PmwikiPmwiki Version2.2.0 Updatebeta33
PmwikiPmwiki Version2.2.0 Updatebeta34
PmwikiPmwiki Version2.2.0 Updatebeta35
PmwikiPmwiki Version2.2.0 Updatebeta36
PmwikiPmwiki Version2.2.0 Updatebeta37
PmwikiPmwiki Version2.2.0 Updatebeta38
PmwikiPmwiki Version2.2.0 Updatebeta39
PmwikiPmwiki Version2.2.0 Updatebeta4
PmwikiPmwiki Version2.2.0 Updatebeta40
PmwikiPmwiki Version2.2.0 Updatebeta41
PmwikiPmwiki Version2.2.0 Updatebeta42
PmwikiPmwiki Version2.2.0 Updatebeta43
PmwikiPmwiki Version2.2.0 Updatebeta44
PmwikiPmwiki Version2.2.0 Updatebeta45
PmwikiPmwiki Version2.2.0 Updatebeta46
PmwikiPmwiki Version2.2.0 Updatebeta47
PmwikiPmwiki Version2.2.0 Updatebeta48
PmwikiPmwiki Version2.2.0 Updatebeta49
PmwikiPmwiki Version2.2.0 Updatebeta5
PmwikiPmwiki Version2.2.0 Updatebeta50
PmwikiPmwiki Version2.2.0 Updatebeta51
PmwikiPmwiki Version2.2.0 Updatebeta52
PmwikiPmwiki Version2.2.0 Updatebeta53
PmwikiPmwiki Version2.2.0 Updatebeta54
PmwikiPmwiki Version2.2.0 Updatebeta55
PmwikiPmwiki Version2.2.0 Updatebeta56
PmwikiPmwiki Version2.2.0 Updatebeta57
PmwikiPmwiki Version2.2.0 Updatebeta58
PmwikiPmwiki Version2.2.0 Updatebeta59
PmwikiPmwiki Version2.2.0 Updatebeta6
PmwikiPmwiki Version2.2.0 Updatebeta60
PmwikiPmwiki Version2.2.0 Updatebeta61
PmwikiPmwiki Version2.2.0 Updatebeta62
PmwikiPmwiki Version2.2.0 Updatebeta63
PmwikiPmwiki Version2.2.0 Updatebeta64
PmwikiPmwiki Version2.2.0 Updatebeta65
PmwikiPmwiki Version2.2.0 Updatebeta66
PmwikiPmwiki Version2.2.0 Updatebeta67
PmwikiPmwiki Version2.2.0 Updatebeta68
PmwikiPmwiki Version2.2.0 Updatebeta7
PmwikiPmwiki Version2.2.0 Updatebeta8
PmwikiPmwiki Version2.2.0 Updatebeta9
PmwikiPmwiki Version2.2.1
PmwikiPmwiki Version2.2.2
PmwikiPmwiki Version2.2.3
PmwikiPmwiki Version2.2.4
PmwikiPmwiki Version2.2.5
PmwikiPmwiki Version2.2.6
PmwikiPmwiki Version2.2.7
PmwikiPmwiki Version2.2.8
PmwikiPmwiki Version2.2.9
PmwikiPmwiki Version2.2.10
PmwikiPmwiki Version2.2.11
PmwikiPmwiki Version2.2.12
PmwikiPmwiki Version2.2.13
PmwikiPmwiki Version2.2.14
PmwikiPmwiki Version2.2.15
PmwikiPmwiki Version2.2.16
PmwikiPmwiki Version2.2.17
PmwikiPmwiki Version2.2.18
PmwikiPmwiki Version2.2.19
PmwikiPmwiki Version2.2.20
PmwikiPmwiki Version2.2.21
PmwikiPmwiki Version2.2.22
PmwikiPmwiki Version2.2.23
PmwikiPmwiki Version2.2.24
PmwikiPmwiki Version2.2.25
PmwikiPmwiki Version2.2.26
PmwikiPmwiki Version2.2.27
PmwikiPmwiki Version2.2.28
PmwikiPmwiki Version2.2.29
PmwikiPmwiki Version2.2.30
PmwikiPmwiki Version2.2.32
PmwikiPmwiki Version2.2.33
PmwikiPmwiki Version2.2.34
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 84.05% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.