CVE-2009-0602
WikkiTikkiTavi 1.11 - Unauthenticated Arbitrary File Upload and Remote Code Execution via upload.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0602. PoCs published by ByALBAYX.
AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in WikkiTikkiTavi. It provides paths for exploitation but lacks actual exploit code or technical details.
Description
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by ByALBAYX · textwebappsphp
https://www.exploit-db.com/exploits/7998
This is a writeup describing an arbitrary file upload vulnerability in WikkiTikkiTavi. It provides paths for exploitation but lacks actual exploit code or technical details.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:
WikkiTikkiTavi (version unspecified)
No auth needed
Prerequisites:
access to the upload.php endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48571
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/33647
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/7998
Scores
EPSS
0.0455
EPSS Percentile
90.4%
Details
CWE
CWE-20
Status
published
Products (1)
wikkitikkitavi/wikkitikkitavi
1.11
Published
Feb 16, 2009
Tracked Since
Feb 18, 2026