CVE-2007-5423: Code Injection
Published Oct 12, 2007
·Updated
tiki-graphformula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by createfunction.
Affected Software
1 affected component
Tiki Wiki CMS Groupware=1.9.8
Event History
Oct 12, 2007
CVE Published
11:17 PM
Oct 13, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5423?
CVE-2007-5423 is rated as critical due to its potential for arbitrary code execution.
2
How do I fix CVE-2007-5423?
To mitigate CVE-2007-5423, upgrade to a patched version of TikiWiki that addresses this vulnerability.
3
What versions of TikiWiki are affected by CVE-2007-5423?
CVE-2007-5423 affects TikiWiki version 1.9.8 specifically.
4
Can CVE-2007-5423 be exploited remotely?
Yes, CVE-2007-5423 can be exploited remotely by attackers to execute arbitrary code.
5
What component of TikiWiki is vulnerable in CVE-2007-5423?
The vulnerability in CVE-2007-5423 is found in the tiki-graph_formula.php file.