PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3946 | exploit vdb entry patch |
http://securitytracker.com/id?1003307 | exploit vdb entry patch |
http://sourceforge.net/mailarchive/message.php?msg_id=185752 | mailing list exploit vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8001 | vdb entry |