PT-2004-2825 · Tiki · Tikiwiki Cms/Groupware

Jeiar

·

Published

2004-04-11

·

Updated

2017-07-11

·

CVE-2004-1927

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tiki CMS/Groupware versions 1.8.1 and earlier
Description A directory traversal issue exists in the map feature of Tiki CMS/Groupware, allowing remote attackers to determine the existence of arbitrary files by using .. (dot dot) sequences in the mapfile parameter of the tiki-map.phtml file.
Recommendations For versions 1.8.1 and earlier, consider restricting access to the tiki-map.phtml file until a fix is available, and avoid using the mapfile parameter with untrusted input.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1927

Affected Products

Tikiwiki Cms/Groupware