actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2012-09-05T20:00:00Z

Updated: 2024-09-16T20:21:27.928Z

Reserved: 2011-11-15T00:00:00Z

Link: CVE-2011-4449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-09-05T20:55:01.163

Modified: 2012-09-07T04:24:00.600

Link: CVE-2011-4449

cve-icon Redhat

No data.