Show filters
154 Total Results
Displaying 91-100 of 154
Sort by:
Attacker Value
Unknown
CVE-2018-7290
Disclosure Date: March 09, 2018 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.
0
Attacker Value
Unknown
CVE-2018-7304
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
0
Attacker Value
Unknown
CVE-2018-7303
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The Calendar component in Tiki 17.1 allows HTML injection.
0
Attacker Value
Unknown
CVE-2018-7302
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
0
Attacker Value
Unknown
CVE-2018-7188
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.
0
Attacker Value
Unknown
CVE-2016-7394
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
0
Attacker Value
Unknown
CVE-2017-14924
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
0
Attacker Value
Unknown
CVE-2017-14925
Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
0
Attacker Value
Unknown
CVE-2017-9145
Disclosure Date: June 26, 2017 (last updated November 26, 2024)
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
0
Attacker Value
Unknown
CVE-2017-9305
Disclosure Date: May 31, 2017 (last updated November 26, 2024)
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.
0