CVE-2007-6412 Information

Description

Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier when comments are enabled allows remote attackers to inject arbitrary PHP code via an editcomments action.

Reference

http://osvdb.org/40148 http://securityreason.com/securityalert/3428 http://securityreason.com/securityalert/3454 http://www.hackerscenter.com/archive/view.asp?id=28129 http://www.securityfocus.com/archive/1/484805/100/0/threaded http://www.securityfocus.com/bid/26801

Share on: