PT-2004-2826 · Tikiwiki · Tikiwiki Cms/Groupware

Publicado

2004-04-12

·

Atualizado

2017-07-11

·

CVE-2004-1928

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tiki CMS/Groupware (TikiWiki) versions 1.8.1 and earlier
Description The issue concerns the image upload feature, which allows remote attackers to upload and possibly execute arbitrary files. This is achieved via the "img/wiki up" URL.
Recommendations For versions 1.8.1 and earlier, consider disabling the image upload feature until a fix is available. Restrict access to the "img/wiki up" URL to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-1928

Produtos afetados

Tikiwiki Cms/Groupware