Vulnerabilities > Tiki > Tikiwiki CMS Groupware > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-12-03 CVE-2008-5318 Multiple Unspecified vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.
network
low complexity
tiki
5.0
2008-08-13 CVE-2008-3654 Remote Security vulnerability in TikiWiki
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.
network
low complexity
tiki
5.0
2008-02-27 CVE-2008-1047 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1
Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
tiki CWE-79
4.3
2007-12-27 CVE-2007-6528 Path Traversal vulnerability in Tiki Tikiwiki Cms/Groupware
Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a ..
network
low complexity
tiki CWE-22
5.0
2007-12-27 CVE-2007-6526 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.
network
tiki CWE-79
4.3
2007-10-26 CVE-2007-5683 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.
network
tiki CWE-79
4.3
2007-08-28 CVE-2007-4554 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.7
Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
network
tiki CWE-79
4.3
2006-12-11 CVE-2006-6457 Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.2/1.9.5
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
network
low complexity
tiki CWE-200
5.0
2006-11-29 CVE-2006-6163 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in TikiWiki before 1.9.7 allows remote attackers to inject arbitrary JavaScript via unspecified parameters.
network
tiki CWE-79
4.3
2006-11-29 CVE-2006-6162 Cross-Site Scripting vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.6
Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter.
network
tiki CWE-79
4.3