Описание
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.2:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00635
Низкий
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
debian
почти 20 лет назад
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remo ...
github
больше 3 лет назад
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.
EPSS
Процентиль: 70%
0.00635
Низкий
5 Medium
CVSS2
Дефекты
CWE-200