Vulnerabilities > Tiki

DATE CVE VULNERABILITY TITLE RISK
2008-02-27 CVE-2008-1047 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1
Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
tiki CWE-79
4.3
2007-12-27 CVE-2007-6529 Remote Security vulnerability in TikiWiki
Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php.
network
low complexity
tiki
critical
10.0
2007-12-27 CVE-2007-6528 Path Traversal vulnerability in Tiki Tikiwiki Cms/Groupware
Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a ..
network
low complexity
tiki CWE-22
5.0
2007-12-27 CVE-2007-6526 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.
network
tiki CWE-79
4.3
2007-10-26 CVE-2007-5684 Path Traversal vulnerability in Tiki Tikiwiki Cms/Groupware
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the imp_language parameter to tiki-imexport_languages.php.
network
low complexity
tiki CWE-22
7.5
2007-10-26 CVE-2007-5683 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.
network
tiki CWE-79
4.3
2007-10-26 CVE-2007-5682 Permissions, Privileges, and Access Controls vulnerability in Tiki Tikiwiki Cms/Groupware
Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using variable functions and variable variables to write variables whose names match the whitelist, a different vulnerability than CVE-2007-5423.
network
low complexity
tiki CWE-264
7.5
2007-10-12 CVE-2007-5423 Code Injection vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.8
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.
network
low complexity
tiki CWE-94
7.5
2007-08-28 CVE-2007-4554 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.7
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
network
tiki CWE-79
4.3
2006-12-11 CVE-2006-6457 Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.2/1.9.5
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
network
low complexity
tiki CWE-200
5.0