← Vulnerability feed

Vulnerability record · CVE-2011-4450 · published 5 September 2012

CVE-2011-4450: Wikkawiki path traversal vulnerability

Wikkawiki · Wikkawiki

Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.

6.4 CVSS 2.0 Medium EPSS 7.5% · top 5.7% CWE-22 · Path traversal
6.4CVSS 2.0 base score
7.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (dot dot) in the file parameter, as demonstrated by the /../../wikka.config.php pathname in a download action.

AV:N/AC:L/Au:N/C:P/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.3CVE-2007-2613Wikkawiki vulnerabilityWikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration f…EPSS 0.55%7.5CVE-2011-4448Wikkawiki sql injection vulnerabilitySQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL co…EPSS 1.9%7.5CVE-2007-2612Wikkawiki vulnerabilitySQL injection vulnerability in libs/Wakka.class.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to execute arbitrary SQL command…EPSS 1.1%7.5CVE-2006-7049Wikkawiki vulnerabilityThe Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote …EPSS 1.7%6.8CVE-2011-4449Wikkawiki vulnerabilityactions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically abs…EPSS 4.1%6.8CVE-2011-4452Wikkawiki cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authen…EPSS 2.3%6.8CVE-2006-7050Wikkawiki vulnerabilityCross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) even…EPSS 1.4%5.0CVE-2007-2552Wikkawiki information exposure vulnerabilityThe RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2011-4450), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.