cbcvebase.
CVE-2007-5682
published 2007-10-26

CVE-2007-5682: Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using variable…

PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.58%
83.3th percentile
Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using variable functions and variable variables to write variables whose names match the whitelist, a different vulnerability than CVE-2007-5423.

Affected

10 ranges
VendorProductVersion rangeFixed in
tikitikiwiki_cms_groupware<= 1.9.8
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
tikitikiwiki_cms_groupware
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.