This application requires Javascript for optimal performance.

PmWiki.Remote.PHP.Code.Injection

Release Date

Jan 07, 2012

Severity

high

Impact

System Compromise: Remote attackers can remote execute arbitrary code.

Description

This indicates an attack attempt to exploit a PHP Code Injection vulnerability in PmWiki.

The vulnerability is a result of the application's failure to properly sanitize user input before using it in PageListSort() function. As a result, a remote attacker can send a crafted request to execute PHP code on a vulnerable server.

Affected Products

PmWiki version 2.0.0 to 2.2.34

Recommended Actions

Upgrade to the latest version, available from the website.
http://www.pmwiki.org/wiki/PmWiki/ChangeLog#v2235

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-4453

Reference/s

http://www.securityfocus.com/bid/50776 (BugTraq)
http://osvdb.org/show/osvdb/77261
http://www.exploit-db.com/exploits/18149/
http://www.pmwiki.org/wiki/PITS/01271

Reference: VID-30654