Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2011-4551
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
0
Attacker Value
Unknown
CVE-2012-3996
Disclosure Date: July 12, 2012 (last updated October 04, 2023)
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
0
Attacker Value
Unknown
CVE-2012-0220
Disclosure Date: May 29, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.
0
Attacker Value
Unknown
CVE-2011-1401
Disclosure Date: April 11, 2011 (last updated October 04, 2023)
ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.
0
Attacker Value
Unknown
CVE-2010-1195
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.
0
Attacker Value
Unknown
CVE-2010-1134
Disclosure Date: March 27, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.
0
Attacker Value
Unknown
CVE-2010-1136
Disclosure Date: March 27, 2010 (last updated October 04, 2023)
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.
0
Attacker Value
Unknown
CVE-2009-2944
Disclosure Date: August 31, 2009 (last updated October 04, 2023)
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.
0