LWN.net Logo

hiki: missing input sanitizing

Package(s):hiki CVE #(s):CVE-2007-2836
Created:June 29, 2007 Updated:July 3, 2007
Description: Kazuhiro Nishiyama found a vulnerability in hiki, a Wiki engine written in Ruby, which could allow a remote attacker to delete arbitrary files which are writable to the Hiki user, via a specially crafted session parameter.
Alerts:
Debian DSA-1324 2007-06-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds