LWN.net Logo

TikiWiki: arbitrary command execution

Package(s):tikiwiki CVE #(s):CVE-2006-4299 CVE-2006-4602
Created:September 26, 2006 Updated:September 27, 2006
Description: A vulnerability in jhot.php allows for an unrestricted file upload to the img/wiki/ directory. Additionally, a cross-site scripting vulnerability exists in the highlight parameter of tiki-searchindex.php.
Alerts:
Gentoo 200609-16 2006-09-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds