Show filters
97 Total Results
Displaying 81-90 of 97
Sort by:
Attacker Value
Unknown

CVE-2006-1196

Disclosure Date: March 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.
0
Attacker Value
Unknown

CVE-2006-0983

Disclosure Date: March 03, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2006-0699

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
0
Attacker Value
Unknown

CVE-2005-3529

Disclosure Date: November 20, 2005 (last updated February 22, 2025)
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.
0
Attacker Value
Unknown

CVE-2005-3528

Disclosure Date: November 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter.
0
Attacker Value
Unknown

CVE-2005-1925

Disclosure Date: November 18, 2005 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.
0
Attacker Value
Unknown

CVE-2005-3283

Disclosure Date: October 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-1921

Disclosure Date: July 05, 2005 (last updated February 22, 2025)
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
0
Attacker Value
Unknown

CVE-2005-0200

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.
0
Attacker Value
Unknown

CVE-2005-0283

Disclosure Date: January 04, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.
0