CVE-2011-4448

WikkaWiki 1.3.1 and 1.3.2 - SQL Injection via default_comment_display Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4448.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in WikkaWiki <= 1.3.2, including SQL injection (CVE-2011-4448), unrestricted file upload (CVE-2011-4449), arbitrary file download/deletion (CVE-2011-4450), and remote code execution (CVE-2011-4451). The writeup includes code snippets, root cause analysis, and proof-of-concept requests.

Description

SQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL commands via the default_comment_display parameter in an update action.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/18177

This is a detailed technical analysis of multiple vulnerabilities in WikkaWiki <= 1.3.2, including SQL injection (CVE-2011-4448), unrestricted file upload (CVE-2011-4449), arbitrary file download/deletion (CVE-2011-4450), and remote code execution (CVE-2011-4451). The writeup includes code snippets, root cause analysis, and proof-of-concept requests.

Classification
Writeup 100%
Attack Type
Sqli | Info Leak | Auth Bypass | Other
Complexity
Moderate
Reliability
Reliable
Target: WikkaWiki <= 1.3.2
Auth required
Prerequisites: Access to the target application · Valid session cookie for authenticated actions
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch x_refsource_confirm
http://wush.net/trac/wikka/changeset/1820
Vendor Advisory x_refsource_confirm
http://wush.net/trac/wikka/ticket/1097

Scores

EPSS 0.0194
EPSS Percentile 77.5%

Details

CWE
CWE-89
Status published
Products (2)
wikkawiki/wikkawiki 1.3.1
wikkawiki/wikkawiki 1.3.2
Published Sep 05, 2012
Tracked Since Feb 18, 2026