tikiwiki: multiple vulnerabilities
| Package(s): | tikiwiki | CVE #(s): | CVE-2007-6528 CVE-2007-6526 CVE-2007-6529 | ||||
| Created: | January 24, 2008 | Updated: | January 30, 2008 | ||||
| Description: | From the Gentoo alert:
Jesus Olmos Gonzalez from isecauditors reported insufficient sanitization of the "movies" parameter in file tiki-listmovies.php (CVE-2007-6528). Mesut Timur from H-Labs discovered that the input passed to the "area_name" parameter in file tiki-special_chars.php is not properly sanitised before being returned to the user (CVE-2007-6526). redflo reported multiple unspecified vulnerabilities in files tiki-edit_css.php, tiki-list_games.php, and tiki-g-admin_shared_source.php (CVE-2007-6529). | ||||||
| Alerts: |
| ||||||
