Vulnerability record · CVE-2011-4453 · published 22 December 2011
CVE-2011-4453: PmWiki pagelist order parameter code injection
Pmwiki · Pmwiki
PmWiki 2.x before 2.2.35 passes the pagelist directive's order parameter into PHP's create_function without adequate sanitization, allowing injected PHP sequences to be executed. Because the flaw is reachable remotely without authentication, it exposes wiki installations to arbitrary code execution.
Description
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploits and very high EPSS, though the product is a niche wiki and the CVE is not in KEV.
What it is
PmWiki 2.x before 2.2.35 passes the pagelist directive's order parameter into PHP's create_function without adequate sanitization, allowing injected PHP sequences to be executed. Because the flaw is reachable remotely without authentication, it exposes wiki installations to arbitrary code execution.
Impact
An attacker can execute arbitrary PHP code on the server, gaining the privileges of the web server process and potentially full control of the wiki host.
Attack surface
Reached remotely over the network by supplying a crafted order parameter in a pagelist directive; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists in Exploit-DB (18149, 18243) and the vendor PITS entry is tagged Exploit and Patch; the CVE is not in CISA KEV, but EPSS is 0.51981 (99th percentile), indicating high predicted exploitation activity.
What to do
- Upgrade PmWiki to 2.2.35 or later, which contains the fix referenced in PITS/01271.
- If immediate upgrade is not possible, restrict or disable use of the pagelist directive's order parameter.
- Place the wiki behind authentication or network restrictions so unauthenticated users cannot reach pagelist functionality.
- Review PHP configuration to limit the impact of code execution (disable dangerous functions where feasible, run the web process with least privilege).
Detection
- Search web server and PHP logs for pagelist requests containing order parameters with PHP function syntax or unusual characters.
- Monitor for unexpected PHP file creation or modification in the PmWiki installation directory.
- Alert on outbound network connections or process spawning from the web server user that are inconsistent with normal wiki operation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/18149/ | Exploit |
| http://www.exploit-db.com/exploits/18243/ | Exploit |
| http://www.pmwiki.org/wiki/PITS/01271 | ExploitPatch |
| http://www.exploit-db.com/exploits/18149/ | Exploit |
| http://www.exploit-db.com/exploits/18243/ | Exploit |
| http://www.pmwiki.org/wiki/PITS/01271 | ExploitPatch |
Track CVE-2011-4453 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4453), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.