Tiki Wiki CMS Groupware v25.0 - Cross Site Scripting
Tiki Wiki CMS Groupware version 25.0 suffers from a cross site scripting vulnerability.
共找到 8 条公开漏洞记录
Tiki Wiki CMS Groupware version 25.0 suffers from a cross site scripting vulnerability.
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Tiki Wiki CMS Groupware 7.0 is vulnerable to cross-site scripting via the GET "ajax" parameter to snarf_ajax.php.
在某些FPM设置配置中,低于7.1.33的PHP版本7.1.x,低于7.2.24的7.2.x和低于7.3.11的7.3.x可能会导致FPM模块将过去分配的缓冲区写入保留给FCGI的空间中协议数据,从而打开了远程执行代码的可能性。
Tiki Wiki CMS Groupware 5.2 is susceptible to a local file inclusion vulnerability.
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection
Tiki Wiki CMS Groupware 5.2 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.