« Volver al listado

CVE-2011-4449

Estado: ModificadaMedia (6.8)—💥 Exploit

El archivo actions/files/files.php en WikkaWiki versiones 1.3.1 y 1.3.2, cuando INTRANET_MODE está habilitado, soporta cargas de archivos para extensiones de archivo que normalmente están ausentes desde un archivo TypesConfig de Apache HTTP Server, lo que le facilita a atacantes remotos ejecutar código PHP arbitrario mediante la colocación de este código en un archivo cuyo nombre tiene varias extensiones, como es demostrado por una archivo (1) .mm o (2) .vpp.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4449",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-05T20:55:01.163",
  "references": [
    {
      "url": "http://wush.net/trac/wikka/changeset/1822",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wush.net/trac/wikka/ticket/1097",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wush.net/trac/wikka/changeset/1822",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wush.net/trac/wikka/ticket/1097",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file."
    },
    {
      "lang": "es",
      "value": "El archivo actions/files/files.php en WikkaWiki versiones 1.3.1 y 1.3.2, cuando INTRANET_MODE está habilitado, soporta cargas de archivos para extensiones de archivo que normalmente están ausentes desde un archivo TypesConfig de Apache HTTP Server, lo que le facilita a atacantes remotos ejecutar código PHP arbitrario mediante la colocación de este código en un archivo cuyo nombre tiene varias extensiones, como es demostrado por una archivo (1) .mm o (2) .vpp."
    }
  ],
  "lastModified": "2026-06-16T23:34:54.273",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63F5FD8C-02BB-4208-AEF8-11797376DA23"
            },
            {
              "criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C44D576A-77E7-4E70-9E17-41E96A9A4A2A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}