CVE-2006-7049
Status: ModifiedHigh (7.5)—
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.65%
- Percentile among all scored CVEs: 76
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://secunia.com/advisories/20628
- http://wikkawiki.org/WikkaReleaseNotes
- http://www.osvdb.org/26543
- http://www.securityfocus.com/bid/18484
- http://www.vupen.com/english/advisories/2006/2381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27226
- http://secunia.com/advisories/20628
- http://wikkawiki.org/WikkaReleaseNotes
- http://www.osvdb.org/26543
- http://www.securityfocus.com/bid/18484
- http://www.vupen.com/english/advisories/2006/2381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27226
Raw JSON (NVD)
Show
{
"id": "CVE-2006-7049",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-02-24T00:28:00.000",
"references": [
{
"url": "http://secunia.com/advisories/20628",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://wikkawiki.org/WikkaReleaseNotes",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/26543",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18484",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2381",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27226",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/20628",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wikkawiki.org/WikkaReleaseNotes",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/26543",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/18484",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2381",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27226",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files."
},
{
"lang": "es",
"value": "El método Method en WikkaWiki (Wikka Wiki) anterior 1.1.6.2 llama a las funciones strstr y strrpos con la orden de argumento erroneo, lo cual permite a atacantes remotos evitar restricciones de acceso intencionados y acceso a archivos PHP de su elección."
}
],
"lastModified": "2026-06-16T22:34:17.320",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.1.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68D9E066-FB0F-470B-9B7B-7401361F97BA"
},
{
"criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.1.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17D503D2-77F1-412C-BD3C-C57B49D67A2E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}