Show filters
147 Total Results
Displaying 101-110 of 147
Sort by:
Attacker Value
Unknown

CVE-2012-0911

Disclosure Date: July 12, 2012 (last updated January 21, 2024)
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.
Attacker Value
Unknown

CVE-2012-3996

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
0
Attacker Value
Unknown

CVE-2010-1135

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.
0
Attacker Value
Unknown

CVE-2010-1134

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.
0
Attacker Value
Unknown

CVE-2010-1133

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.
0
Attacker Value
Unknown

CVE-2010-1136

Disclosure Date: March 27, 2010 (last updated October 04, 2023)
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.
0
Attacker Value
Unknown

CVE-2003-1574

Disclosure Date: August 24, 2009 (last updated October 04, 2023)
TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-1204

Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.
0
Attacker Value
Unknown

CVE-2008-5318

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.
0
Attacker Value
Unknown

CVE-2008-5319

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.
0