PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wikkitikkitavi | Wikkitikkitavi | 0.5 (including) | 0.5 (including) |
Wikkitikkitavi | Wikkitikkitavi | 0.10 (including) | 0.10 (including) |
Wikkitikkitavi | Wikkitikkitavi | 0.20 (including) | 0.20 (including) |