|
|
| |
|
| |
tikiwiki: multiple vulnerabilities
| Package(s): | tikiwiki |
CVE #(s): | CVE-2006-5702
CVE-2006-5703
|
| Created: | November 21, 2006 |
Updated: | November 21, 2006 |
| Description: |
In numerous files TikiWiki provides an empty sort_mode parameter, causing
TikiWiki to display additional information, including database
authentication credentials, in certain error messages. TikiWiki also
improperly sanitizes the "url" request variable sent to
tiki-featured_link.php. |
| Alerts: |
|
( Log in to post comments)
|
|
|