WikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration file by modifying the WAKKA_CONFIG environment variable. The vendor has addressed this issue through a product update:
http://www.wikkawiki.org/downloads/
Publication date: Fri, 11 May 2007 15:19:00 +0000