CVE-2007-5423
Tikiwiki Cms/groupware - Code Injection
Title source: ruleDescription
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16911
metasploit
WORKING POC
EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tikiwiki_graph_formula_exec.rb
References (15)
Scores
EPSS
0.8808
EPSS Percentile
99.5%
Details
CWE
CWE-94
Status
published
Products (1)
tiki/tikiwiki_cms\/groupware
1.9.8
Published
Oct 12, 2007
Tracked Since
Feb 18, 2026