Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
Authentication bypass via repeated parameters
Disclosure Date: April 13, 2018 (last updated November 26, 2024)
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
0
Attacker Value
Unknown
Commit metadata forgery via CGI::FormBuilder context-dependent APIs
Disclosure Date: April 13, 2018 (last updated November 26, 2024)
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
0