CVE-2017-7981
Published Apr 29, 2017Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wi…
Vendor/product archive
2 CVEs tagged to phpwiki_project / phpwiki — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used wi…
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp…