CVE-2006-4602
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.
Vulnerabilidad de actualización de fichero no restringida en jhot.php en TikiWiki 1.9.4 Sirius y anteriores, permite a un atacante remoto ejecutar código PHP de su elección a través del parámetro filepath que contiene un nombre de fichero con una extensión .php, lo cual es actualizado en el directorio img/wiki/.
TikiWiki contains a flaw that may allow a malicious user to execute arbitrary PHP code. The issue is triggered due to the jhot.php script not correctly verifying uploaded files. It is possible that the flaw may allow arbitrary PHP code execution by uploading a malicious PHP script resulting in a loss of integrity. The vulnerability has been reported in Tikiwiki version 1.9.4.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-06 CVE Reserved
- 2006-09-07 CVE Published
- 2010-07-25 First Exploit
- 2024-01-30 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://isc.sans.org/diary.php?storyid=1672 | X_refsource_misc | |
http://tikiwiki.org/tiki-read_article.php?articleId=136 | X_refsource_confirm | |
http://www.osvdb.org/28456 | Vdb Entry | |
http://web.archive.org/web/20061013183145/http://secunia.com:80/advisories/21733 |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/2288 | 2024-08-07 | |
https://www.exploit-db.com/exploits/16885 | 2010-07-25 | |
http://www.securityfocus.com/bid/19819 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21733 | 2017-10-19 | |
http://secunia.com/advisories/22100 | 2017-10-19 | |
http://security.gentoo.org/glsa/glsa-200609-16.xml | 2017-10-19 | |
http://www.vupen.com/english/advisories/2006/3450 | 2017-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tiki Search vendor "Tiki" | Tikiwiki Cms\/groupware Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" | 1.9.4 Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.4" | - |
Affected
|