CVE-2011-4449
Status: ModifiedMedium (6.8)—💥 Exploit
actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.14%
- Percentile among all scored CVEs: 91
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · WikkaWiki 1.3.2 - Spam Logging PHP Injection (Metasploit) (5/12/2012)
- Published on Exploit-DB · WikkaWiki 1.3.2 - Multiple Vulnerabilities (11/30/2011)
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2011-4449",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-09-05T20:55:01.163",
"references": [
{
"url": "http://wush.net/trac/wikka/changeset/1822",
"tags": [
"Exploit",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://wush.net/trac/wikka/ticket/1097",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://wush.net/trac/wikka/changeset/1822",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wush.net/trac/wikka/ticket/1097",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server TypesConfig file, which makes it easier for remote attackers to execute arbitrary PHP code by placing this code in a file whose name has multiple extensions, as demonstrated by a (1) .mm or (2) .vpp file."
},
{
"lang": "es",
"value": "El archivo actions/files/files.php en WikkaWiki versiones 1.3.1 y 1.3.2, cuando INTRANET_MODE está habilitado, soporta cargas de archivos para extensiones de archivo que normalmente están ausentes desde un archivo TypesConfig de Apache HTTP Server, lo que le facilita a atacantes remotos ejecutar código PHP arbitrario mediante la colocación de este código en un archivo cuyo nombre tiene varias extensiones, como es demostrado por una archivo (1) .mm o (2) .vpp."
}
],
"lastModified": "2026-06-16T23:34:54.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63F5FD8C-02BB-4208-AEF8-11797376DA23"
},
{
"criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C44D576A-77E7-4E70-9E17-41E96A9A4A2A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}