LWN.net Logo

tikiwiki: multiple vulnerabilities

Package(s):tikiwiki CVE #(s):CVE-2006-5702 CVE-2006-5703
Created:November 21, 2006 Updated:November 21, 2006
Description: In numerous files TikiWiki provides an empty sort_mode parameter, causing TikiWiki to display additional information, including database authentication credentials, in certain error messages. TikiWiki also improperly sanitizes the "url" request variable sent to tiki-featured_link.php.
Alerts:
Gentoo 200611-11 2006-11-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds