Show filters
154 Total Results
Displaying 71-80 of 154
Sort by:
Attacker Value
Unknown

CVE-2013-6022

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2011-4558

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
Attacker Value
Unknown

CVE-2011-4336

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
Attacker Value
Unknown

CVE-2011-4455

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.
Attacker Value
Unknown

CVE-2011-4454

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.
Attacker Value
Unknown

CVE-2010-4240

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has XSS
Attacker Value
Unknown

CVE-2010-4239

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Attacker Value
Unknown

CVE-2010-4241

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Tiki Wiki CMS Groupware 5.2 has CSRF
Attacker Value
Unknown

CVE-2019-15314

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
0
Attacker Value
Unknown

CVE-2018-20719

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
0