This CVE name corresponds to:
Entered | Topic |
---|---|
2007-11-09 | tikiwiki -- multiple vulnerabilities |
The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.
Type | Candidate |
Name | CVE-2007-5684 |
Phase | Assigned(20071026) |
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the imp_language parameter to tiki-imexport_languages.php.
Source | Reference |
---|---|
BUGTRAQ | 20071025 TikiWiki <= 1.9.8.1 Cross Site Scripting / Local File Inclusion |
CONFIRM | http://info.tikiwiki.org/tiki-read_article.php?articleId=15 |
Copyright © 2005 The MITRE Corporation.
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright
information.