Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2006-7049 | First vendor Publication | 2007-02-23 |
| Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
| Cvss vector : N/A | |||
|---|---|---|---|
| Overall CVSS Score | NA | ||
| Base Score | NA | Environmental Score | NA |
| impact SubScore | NA | Temporal Score | NA |
| Exploitabality Sub Score | NA | ||
| Calculate full CVSS 3.0 Vectors scores | |||
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentication | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
| The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7049 |
CWE : Common Weakness Enumeration
| % | Id | Name |
|---|
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 2 |
Open Source Vulnerability Database (OSVDB)
| Id | Description |
|---|---|
| 26543 | WikkaWiki wikka.php Method() Function Arbitrary Page Access WikkaWiki contains a flaw that allows a remote arbitrary page access. This flaw exists because the application does not use correctly the strstr() function within the Method() function upon submission to the wikka.php script. This could allow a user to create a specially crafted URL that would allow arbitrary page access leading to a loss of integrity. |
Nessus® Vulnerability Scanner
| Date | Description |
|---|---|
| 2006-06-17 | Name : The remote web server contains a PHP script that is affected by a local file ... File : wikka_method_name_info_disclosure.nasl - Type : ACT_ATTACK |
Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2024-11-28 23:18:08 |
|
| 2024-11-28 12:11:02 |
|
| 2021-05-04 12:05:06 |
|
| 2021-04-22 01:05:39 |
|
| 2020-05-23 00:18:57 |
|
| 2017-07-29 12:01:52 |
|
| 2016-06-28 16:02:26 |
|
| 2016-04-26 15:32:23 |
|
| 2014-02-17 10:38:19 |
|
| 2013-05-11 11:18:40 |
|








