WikkaWiki <= 1.3.2 (files.php) Unrestricted File Upload Vulnerability


WikkaWiki contains a flaw that allows a remote user to execute arbitrary PHP code due to the actions/files/files.php script not properly verify user-uploaded files. When INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file with multiple extensions.


Disclosure Date:

November 30, 2011