Security Advisory

CVE-2011-4450

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-09-05 20:00:00
Last updated 2024-09-16 19:51:52
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.