Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

Authentication bypass via repeated parameters

Disclosure Date: April 13, 2018 (last updated October 06, 2023)
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
Attacker Value
Unknown

Commit metadata forgery via CGI::FormBuilder context-dependent APIs

Disclosure Date: April 13, 2018 (last updated October 06, 2023)
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.