PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.
| Software | From | Fixed in |
|---|---|---|
| wikkitikkitavi / wikkitikkitavi | 0.5 | 0.5.x |
| wikkitikkitavi / wikkitikkitavi | 0.20 | 0.20.x |
| wikkitikkitavi / wikkitikkitavi | 0.10 | 0.10.x |