CVE-2008-3654
https://notcve.org/view.php?id=CVE-2008-3654
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors. Vulnerabilidad no especificada en TikiWiki CMS/Groupware antes de 2.0 permite a atacantes obtener "la ruta y la configuración PHP" mediante vectores desconocidos. • http://info.tikiwiki.org/tiki-read_article.php?articleId=35 http://tikiwiki.org/ReleaseNotes20 https://exchange.xforce.ibmcloud.com/vulnerabilities/44421 •
CVE-2008-1047
https://notcve.org/view.php?id=CVE-2008-1047
Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en tiki-edit_article.php de TikiWiki before 1.9.10.1 permite a atacantes remotos inyectar web script o HTML de su elección a través de vectores no especificados. • http://dev.tikiwiki.org/tiki-view_tracker_item.php?itemId=1498 http://secunia.com/advisories/29092 http://tikiwiki.org/ReleaseNotes1910 http://www.securityfocus.com/bid/27968 http://www.vupen.com/english/advisories/2008/0661 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-6526
https://notcve.org/view.php?id=CVE-2007-6526
Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter. Vulnerabilidad de comandos en sitios cruzados (XSS), en el archivo tiki-special_chars.php de TikiWiki, en versiones anteriores a la 1.9.9. Permite que atacantes remotos injecten, a su elección, códigos web o HTML, a través del parámetro area_name. • http://osvdb.org/41179 http://secunia.com/advisories/28225 http://secunia.com/advisories/28602 http://security.gentoo.org/glsa/glsa-200801-10.xml http://securityreason.com/securityalert/3483 http://tikiwiki.org/ReleaseProcess199 http://www.h-labs.org/blog/2007/12/24/tikiwiki_1_9_8_3_tiki_special_chars_php_xss_vulnerability.html http://www.securityfocus.com/archive/1/485483/100/0/threaded http://www.securityfocus.com/bid/27004 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-6528 – TikiWiki Project < 1.9.9 - 'tiki-listmovies.php' Directory Traversal
https://notcve.org/view.php?id=CVE-2007-6528
Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter. Vulnerabilidad de salto de directorio en tiki-listmovies.php en TikiWiki versiones anteriores a 1.9.9 permite a atacantes remotos leer ficheros de su elección mediante un .. (punto punto) y un nombre de fichero modificado en el parámetro movie. • https://www.exploit-db.com/exploits/4942 http://osvdb.org/41178 http://secunia.com/advisories/28225 http://secunia.com/advisories/28602 http://security.gentoo.org/glsa/glsa-200801-10.xml http://securityreason.com/securityalert/3484 http://tikiwiki.org/ReleaseProcess199 http://www.securityfocus.com/archive/1/485482/100/0/threaded http://www.securityfocus.com/bid/27008 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2007-6529
https://notcve.org/view.php?id=CVE-2007-6529
Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php. Múltiples vulnerabilidades no especificadas en TikiWiki anterior a 1.9.9 tienen impacto y vectores de ataque desconocidos involucrando (1) tiki-edit_css.php, (2) tiki-list_games.php, o (3) tiki-g-admin_shared_source.php. • http://osvdb.org/41175 http://osvdb.org/41176 http://osvdb.org/41177 http://secunia.com/advisories/28225 http://secunia.com/advisories/28602 http://security.gentoo.org/glsa/glsa-200801-10.xml http://tikiwiki.org/ReleaseProcess199 •