UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Moniwiki | Moniwiki | 1.0.8 (including) | 1.0.8 (including) |
| Moniwiki | Moniwiki | 1.0.9 (including) | 1.0.9 (including) |
| Moniwiki | Moniwiki | 1.0.9.1 (including) | 1.0.9.1 (including) |