CVE-2007-5683

Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php.
Configurations

Configuration 1

cpe:2.3:a:tiki:tikiwiki_cms/groupware:*:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.8:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.0:rc3:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.6:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms/groupware:1.9.7:*:*:*:*:*:*:*

Information

Published : 2007-10-26 06:46

Updated : 2012-10-24 04:00


NVD link : CVE-2007-5683

Mitre link : CVE-2007-5683

Products Affected
No products.
CWE