// For flags

CVE-2007-6528

TikiWiki Project < 1.9.9 - 'tiki-listmovies.php' Directory Traversal

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

Vulnerabilidad de salto de directorio en tiki-listmovies.php en TikiWiki versiones anteriores a 1.9.9 permite a atacantes remotos leer ficheros de su elección mediante un .. (punto punto) y un nombre de fichero modificado en el parámetro movie.

Jesus Olmos Gonzalez from isecauditors reported insufficient sanitization of the movies parameter in file tiki-listmovies.php. Mesut Timur from H-Labs discovered that the input passed to the "area_name" parameter in file tiki-special_chars.php is not properly sanitised before being returned to the user. redflo reported multiple unspecified vulnerabilities in files tiki-edit_css.php, tiki-list_games.php, and tiki-g-admin_shared_source.php. Versions less than 1.9.9 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-12-27 CVE Reserved
  • 2007-12-27 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
<= 1.9.8
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version " <= 1.9.8"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.6.1
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.6.1"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.0
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.0"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.0
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.0"
rc1
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.0
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.0"
rc2
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.0
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.0"
rc3
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.1
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.1"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.2
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.2"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.3
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.3"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.4
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.4"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.5
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.5"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.6
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.6"
-
Affected
Tiki
Search vendor "Tiki"
Tikiwiki Cms\/groupware
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware"
1.9.7
Search vendor "Tiki" for product "Tikiwiki Cms\/groupware" and version "1.9.7"
-
Affected