TikiWiki项目的多个输入验证漏洞

TikiWiki项目的多个输入验证漏洞

漏洞ID 1107869 漏洞类型 代码注入
发布时间 2004-04-12 更新时间 2005-10-20
图片[1]-TikiWiki项目的多个输入验证漏洞-安全小百科CVE编号 CVE-2004-1926
图片[2]-TikiWiki项目的多个输入验证漏洞-安全小百科CNNVD-ID CNNVD-200404-012
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23951
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200404-012
|漏洞详情
TikiCMS/Groupware(TikiWiki)1.8.1以及之前的版本存在漏洞。远程攻击者借助(1)Theme,(2)Country,(3)RealName,或(4)UserProfile里的Displayedtimezone字段,或Directory/AddSiteoperation里的(5)Name,(6)Description,(7)URL,or(8)Country字段注入任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/10100/info
    
Multiple vulnerabilities have been identified in various modules of the application. These vulnerabilities may allow a remote attacker to carry out various attacks such as path disclosure, cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload.

Directory > Add Site > Name
Directory > Add Site > Description
Directory > Add Site > URL
Directory > Add Site > Country
|参考资料

来源:BID
名称:10100
链接:http://www.securityfocus.com/bid/10100
来源:tikiwiki.org
链接:http://tikiwiki.org/tiki-read_article.php?articleId=66
来源:SECUNIA
名称:11344
链接:http://secunia.com/advisories/11344
来源:BUGTRAQ
名称:20040412MultipleVulnerabilitiesInTikiCMS/Groupware[TikiWiki]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108180073206947&w;=2

相关推荐: Zentrack Debug Mode Information Disclosure Weakness

Zentrack Debug Mode Information Disclosure Weakness 漏洞ID 1100145 漏洞类型 Input Validation Error 发布时间 2003-06-06 更新时间 2003-06-06 CVE编号…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享