WikkaWiki <= 1.3.2 (files.xml.php) Path Traversal Vulnerability


WikkaWiki contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the /handlers/files.xml/files.xml.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack may allow an attacker to access and delete arbitrary files.


Disclosure Date:

November 30, 2011