Vulnerabilities > Tiki > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-12-27 CVE-2007-6526 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.
network
tiki CWE-79
4.3
2007-10-26 CVE-2007-5683 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.
network
tiki CWE-79
4.3
2007-08-28 CVE-2007-4554 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.7
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
network
tiki CWE-79
4.3
2006-12-11 CVE-2006-6457 Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.2/1.9.5
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
network
low complexity
tiki CWE-200
5.0
2006-11-29 CVE-2006-6163 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in TikiWiki before 1.9.7 allows remote attackers to inject arbitrary JavaScript via unspecified parameters.
network
tiki CWE-79
4.3
2006-11-29 CVE-2006-6162 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.6
Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter.
network
tiki CWE-79
4.3
2006-11-04 CVE-2006-5703 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.5
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements.
network
tiki CWE-79
4.3
2006-11-04 CVE-2006-5702 Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.5
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.
network
low complexity
tiki CWE-200
5.0
2006-08-23 CVE-2006-4299 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.4
Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.
network
tiki CWE-79
4.3
2006-06-16 CVE-2006-3047 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
network
tiki CWE-79
4.3