← Vulnerability feed

Vulnerability record · CVE-2006-7049 · published 24 February 2007

CVE-2006-7049: Wikkawiki vulnerability

Wikkawiki · Wikkawiki

The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.

7.5 CVSS 2.0 High EPSS 1.7% · top 24.4%
7.5CVSS 2.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-7049 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.3CVE-2007-2613Wikkawiki vulnerabilityWikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration f…EPSS 0.55%7.5CVE-2011-4448Wikkawiki sql injection vulnerabilitySQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL co…EPSS 1.9%7.5CVE-2007-2612Wikkawiki vulnerabilitySQL injection vulnerability in libs/Wakka.class.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to execute arbitrary SQL command…EPSS 1.1%6.8CVE-2011-4449Wikkawiki vulnerabilityactions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically abs…EPSS 4.1%6.8CVE-2011-4452Wikkawiki cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authen…EPSS 2.3%6.8CVE-2006-7050Wikkawiki vulnerabilityCross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) even…EPSS 1.4%6.4CVE-2011-4450Wikkawiki path traversal vulnerabilityDirectory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrar…EPSS 7.5%5.0CVE-2007-2552Wikkawiki information exposure vulnerabilityThe RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2006-7049), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.