CVE-2007-5423

Tikiwiki Cms/groupware - Code Injection

Title source: rule

Description

tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16911
exploitdb WORKING POC VERIFIED
by ShAnKaR · textwebappsphp
https://www.exploit-db.com/exploits/4509
metasploit WORKING POC EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tikiwiki_graph_formula_exec.rb

Scores

EPSS 0.8808
EPSS Percentile 99.5%

Details

CWE
CWE-94
Status published
Products (1)
tiki/tikiwiki_cms\/groupware 1.9.8
Published Oct 12, 2007
Tracked Since Feb 18, 2026