← Vulnerability feed

Vulnerability record · CVE-2011-4451 · published 5 September 2012

CVE-2011-4451: Wikkawiki vulnerability

Wikkawiki · Wikkawiki

libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter

4.3 CVSS 2.0 Medium EPSS 14% · top 3.5%
4.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4451 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.3CVE-2007-2613Wikkawiki vulnerabilityWikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration f…EPSS 0.55%7.5CVE-2011-4448Wikkawiki sql injection vulnerabilitySQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL co…EPSS 1.9%7.5CVE-2007-2612Wikkawiki vulnerabilitySQL injection vulnerability in libs/Wakka.class.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to execute arbitrary SQL command…EPSS 1.1%7.5CVE-2006-7049Wikkawiki vulnerabilityThe Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote …EPSS 1.7%6.8CVE-2011-4449Wikkawiki vulnerabilityactions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically abs…EPSS 4.1%6.8CVE-2011-4452Wikkawiki cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authen…EPSS 2.3%6.8CVE-2006-7050Wikkawiki vulnerabilityCross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) even…EPSS 1.4%6.4CVE-2011-4450Wikkawiki path traversal vulnerabilityDirectory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrar…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2011-4451), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.