Show filters
97 Total Results
Displaying 11-20 of 97
Sort by:
Attacker Value
Unknown

CVE-2010-4240

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has XSS
Attacker Value
Unknown

CVE-2010-4239

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Attacker Value
Unknown

CVE-2010-4241

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has CSRF
Attacker Value
Unknown

CVE-2019-15314

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
0
Attacker Value
Unknown

CVE-2019-9187

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
0
Attacker Value
Unknown

CVE-2018-20719

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
0
Attacker Value
Unknown

CVE-2018-14849

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.
0
Attacker Value
Unknown

CVE-2018-14850

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.
0
Attacker Value
Unknown

Authentication bypass via repeated parameters

Disclosure Date: April 13, 2018 (last updated November 26, 2024)
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
0
Attacker Value
Unknown

Commit metadata forgery via CGI::FormBuilder context-dependent APIs

Disclosure Date: April 13, 2018 (last updated November 26, 2024)
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
0