AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-4451

MEDIUM · CVSS 4.3 EPSS 14.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-09-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2011-4451
Severity
MEDIUM
CVSS
4.3
EPSS
14.17%

Original NVD Description

libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the User-Agent HTTP header in an addcomment request. NOTE: the vendor disputes this issue because the rendering of the spamlog_path file never uses the PHP interpreter