Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200705-16
https://security.gentoo.org/
Severity: High
Title: PhpWiki: Remote execution of arbitrary code
Date: May 17, 2007
Bugs: #174451
ID: 200705-16
Synopsis
=======
A vulnerability has been discovered in PhpWiki allowing for the remote
execution of arbitrary code.
Background
=========
PhpWiki is an open source content management system written in PHP.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-apps/phpwiki < 1.3.10-r3 >= 1.3.10-r3
==========
Harold Hallikainen has reported that the Upload page fails to properly
check the extension of a file.
Impact
=====
A remote attacker could upload a specially crafted PHP file...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.