TikiWiki项目多个输入验证漏洞

TikiWiki项目多个输入验证漏洞

漏洞ID 1107895 漏洞类型 路径遍历
发布时间 2004-04-12 更新时间 2005-10-20
图片[1]-TikiWiki项目多个输入验证漏洞-安全小百科CVE编号 CVE-2004-1927
图片[2]-TikiWiki项目多个输入验证漏洞-安全小百科CNNVD-ID CNNVD-200404-014
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23949
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200404-014
|漏洞详情
TikiCMS/Groupware(TikiWiki)1.8.1及其早期版本中的地图功能(tiki-map.phtml)存在目录遍历漏洞。远程攻击者可以通过mapfile参数中的..(点点)序列确定任意文件的存在。
|漏洞EXP
source: http://www.securityfocus.com/bid/10100/info
  
Multiple vulnerabilities have been identified in various modules of the application. These vulnerabilities may allow a remote attacker to carry out various attacks such as path disclosure, cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload.

/tiki-map.phtml?mapfile=../../../../var/
|参考资料

来源:XF
名称:tikiwiki-tikimap-file-disclosure(15848)
链接:http://xforce.iss.net/xforce/xfdb/15848
来源:BID
名称:10100
链接:http://www.securityfocus.com/bid/10100
来源:tikiwiki.org
链接:http://tikiwiki.org/tiki-read_article.php?articleId=66
来源:SECUNIA
名称:11344
链接:http://secunia.com/advisories/11344
来源:BUGTRAQ
名称:20040412MultipleVulnerabilitiesInTikiCMS/Groupware[TikiWiki]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108180073206947&w;=2

相关推荐: Megacomputing Personal-WebServer Professional Denial Of Service Vulnerability

Megacomputing Personal-WebServer Professional Denial Of Service Vulnerability 漏洞ID 1099573 漏洞类型 Failure to Handle Exceptional Cond…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享