Show filters
194 Total Results
Displaying 11-20 of 194
Sort by:
Attacker Value
Unknown

CVE-2020-29254

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.
Attacker Value
Unknown

CVE-2020-8034

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
Attacker Value
Unknown

CVE-2020-8035

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
Attacker Value
Unknown

CVE-2020-7804

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.
Attacker Value
Unknown

CVE-2020-8966

Disclosure Date: March 31, 2020 (last updated February 21, 2025)
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
Attacker Value
Unknown

CVE-2020-8866

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within add.php. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10125.
Attacker Value
Unknown

CVE-2020-8865

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template] parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the www-data user. Was ZDI-CAN-10469.
Attacker Value
Unknown

CVE-2020-8518

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
Attacker Value
Unknown

CVE-2013-6022

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2011-4336

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.