|
|
| |
|
| |
hiki: missing input sanitizing
| Package(s): | hiki |
CVE #(s): | CVE-2007-2836
|
| Created: | June 29, 2007 |
Updated: | July 3, 2007 |
| Description: |
Kazuhiro Nishiyama found a vulnerability in hiki, a Wiki engine written in
Ruby, which could allow a remote attacker to delete arbitrary files which
are writable to the Hiki user, via a specially crafted session parameter. |
| Alerts: |
|
( Log in to post comments)
|
|
|