CVE-2006-4602: High severity tiki tikiwiki cms\/groupware vulnerability
Published Sep 7, 2006
·Updated
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.
Affected Software
1 affected component
Tiki Wiki CMS Groupware=1.9.4
Event History
Sep 7, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4602?
CVE-2006-4602 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-4602?
To fix CVE-2006-4602, upgrade TikiWiki to a version later than 1.9.4.
3
What type of vulnerability is CVE-2006-4602?
CVE-2006-4602 is an unrestricted file upload vulnerability.
4
What systems are affected by CVE-2006-4602?
CVE-2006-4602 affects TikiWiki versions 1.9.4 Sirius and earlier.
5
Can CVE-2006-4602 allow attackers to execute arbitrary code?
Yes, CVE-2006-4602 allows remote attackers to execute arbitrary PHP code on the server.