Page 2 of 12 results (0.001 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

21 Feb 2018 — Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS. Tiki 17.1 permite la subida de un archivo .PNG que, en realidad, tiene contenido SVG, lo que conduce a XSS. • https://websecnerd.blogspot.in/2018/01/tiki-wiki-cms-groupware-17.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

21 Feb 2018 — Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation. Tiki 17.1 no valida las entradas de usuario para caracteres especiales, lo que provoca que un ataque de inyección CSV pueda abrir una ventana CMD.EXE o Calculator en la máquina de la víctima para realizar actividades maliciosas. Esto se demuestra... • https://websecnerd.blogspot.in/2018/01/tiki-wiki-cms-groupware-17.html • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •