Unrated severityNVD Advisory· Published Sep 7, 2006· Updated Apr 16, 2026
CVE-2006-4602
CVE-2006-4602
Description
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.
Affected products
1- cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/19819nvdExploit
- secunia.com/advisories/21733nvdVendor Advisory
- secunia.com/advisories/22100nvdVendor Advisory
- www.vupen.com/english/advisories/2006/3450nvdVendor Advisory
- isc.sans.org/diary.phpnvd
- security.gentoo.org/glsa/glsa-200609-16.xmlnvd
- tikiwiki.org/tiki-read_article.phpnvd
- www.osvdb.org/28456nvd
- www.exploit-db.com/exploits/2288nvd
News mentions
0No linked articles in our index yet.