PT-2004-2821 · Tikiwiki · Tikiwiki Cms/Groupware

Jeiar

·

Published

2004-04-11

·

Updated

2017-07-11

·

CVE-2004-1923

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tiki CMS/Groupware (TikiWiki) versions 1.8.1 and earlier
Description The issue allows remote attackers to gain sensitive information via direct requests to specific API endpoints, including "banner click.php", "categorize.php", "tiki-admin include directory.php", and "tiki-directory search.php". These endpoints reveal the web server path in an error message.
Recommendations For versions 1.8.1 and earlier, consider restricting access to the vulnerable API endpoints "banner click.php", "categorize.php", "tiki-admin include directory.php", and "tiki-directory search.php" to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1923

Affected Products

Tikiwiki Cms/Groupware