Количество 3
Количество 3
CVE-2018-7304
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
CVE-2018-7304
Tiki 17.1 does not validate user input for special characters; consequ ...
GHSA-rw22-q8xf-9qv3
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-7304 Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation. | CVSS3: 8.8 | 0% Низкий | почти 8 лет назад | |
CVE-2018-7304 Tiki 17.1 does not validate user input for special characters; consequ ... | CVSS3: 8.8 | 0% Низкий | почти 8 лет назад | |
GHSA-rw22-q8xf-9qv3 Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу