TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
BID:19819
CVE-2006-4602 |Info
TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
| Bugtraq ID: | 19819 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4602 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2006 12:00AM |
| Updated: | Sep 27 2006 06:31PM |
| Credit: | rgod has been credited with the discovery of this vulnerability. |
| Vulnerable: |
TikiWiki Project TikiWiki 1.9.4 TikiWiki Project TikiWiki 1.9.3 1 TikiWiki Project TikiWiki 1.9.2 TikiWiki Project TikiWiki 1.9.1 .1 TikiWiki Project TikiWiki 1.9.1 TikiWiki Project TikiWiki 1.9 -rc3.1 TikiWiki Project TikiWiki 1.9 -rc3 TikiWiki Project TikiWiki 1.9 -rc2 TikiWiki Project TikiWiki 1.9 -rc1 TikiWiki Project TikiWiki 1.8.5 TikiWiki Project TikiWiki 1.8.4 TikiWiki Project TikiWiki 1.8.3 TikiWiki Project TikiWiki 1.8.2 TikiWiki Project TikiWiki 1.8.1 TikiWiki Project TikiWiki 1.8 TikiWiki Project TikiWiki 1.7.9 TikiWiki Project TikiWiki 1.7.8 TikiWiki Project TikiWiki 1.7.7 TikiWiki Project TikiWiki 1.7.6 TikiWiki Project TikiWiki 1.7.5 TikiWiki Project TikiWiki 1.7.4 TikiWiki Project TikiWiki 1.7.3 TikiWiki Project TikiWiki 1.7.2 TikiWiki Project TikiWiki 1.7.1 .1 TikiWiki Project TikiWiki 1.6.1 TikiWiki Project TikiWiki 1.9.3.2 Gentoo Linux |
| Not Vulnerable: | |
Discussion
TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
TikiWiki is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute arbitrary system commands with the privileges of the webserver process.
TikiWiki 1.9.4 and prior versions are vulnerable to these issues; other versions may also be affected.
TikiWiki is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute arbitrary system commands with the privileges of the webserver process.
TikiWiki 1.9.4 and prior versions are vulnerable to these issues; other versions may also be affected.
Exploit / POC
TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
Attackers can exploit this issue via a web client.
The following exploit code is available:
Attackers can exploit this issue via a web client.
The following exploit code is available:
Solution / Fix
TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
References:
References:
- PmWiki Home Page (PmWiki)