CVE-2012-3996

TikiWiki CMS/Groupware < 8.2 - Exposure of Sensitive Information via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-3996. PoCs published by Metasploit, EgiX.

AI-analyzed exploit summary This Metasploit module exploits a PHP unserialize() vulnerability in Tiki Wiki <= 8.3 to achieve remote code execution by leveraging the __destruct() method of the Zend_Pdf_ElementFactory_Proxy class to write arbitrary PHP code to a file on the web server.

Description

TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/19630

This Metasploit module exploits a PHP unserialize() vulnerability in Tiki Wiki <= 8.3 to achieve remote code execution by leveraging the __destruct() method of the Zend_Pdf_ElementFactory_Proxy class to write arbitrary PHP code to a file on the web server.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Tiki Wiki <= 8.3
No auth needed
Prerequisites: display_errors PHP setting must be On · Tiki Wiki Multiprint feature must be enabled · PHP version older than 5.3.4
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/19573

This exploit leverages a PHP deserialization vulnerability in Tiki Wiki CMS Groupware <= 8.3 to achieve remote code execution. It constructs a malicious serialized object using Zend Framework classes to write a PHP shell to the target system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Tiki Wiki CMS Groupware <= 8.3
No auth needed
Prerequisites: Target must be running Tiki Wiki CMS Groupware <= 8.3 · Multi-print feature must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19630
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19573
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/83533
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-07/0020.html
Patch x_refsource_misc
http://dev.tiki.org/item4109

Scores

EPSS 0.0459
EPSS Percentile 90.4%

Details

CWE
CWE-200
Status published
Products (24)
tiki/tikiwiki_cms\/groupware 2.2
tiki/tikiwiki_cms\/groupware 3.0
tiki/tikiwiki_cms\/groupware 3.1
tiki/tikiwiki_cms\/groupware 3.2
tiki/tikiwiki_cms\/groupware 3.3
tiki/tikiwiki_cms\/groupware 3.4
tiki/tikiwiki_cms\/groupware 3.5
tiki/tikiwiki_cms\/groupware 4
tiki/tikiwiki_cms\/groupware 4.0
tiki/tikiwiki_cms\/groupware 4.1
... and 14 more
Published Jul 12, 2012
Tracked Since Feb 18, 2026