PT-2004-2826 · Tikiwiki · Tikiwiki Cms/Groupware

Published

2004-04-12

·

Updated

2017-07-11

·

CVE-2004-1928

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tiki CMS/Groupware (TikiWiki) versions 1.8.1 and earlier
Description The issue concerns the image upload feature, which allows remote attackers to upload and possibly execute arbitrary files. This is achieved via the "img/wiki up" URL.
Recommendations For versions 1.8.1 and earlier, consider disabling the image upload feature until a fix is available. Restrict access to the "img/wiki up" URL to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-1928

Affected Products

Tikiwiki Cms/Groupware