Molteplici cross-site scripting (XSS) vulnerabilità in Tiki CMS / Groupware (TikiWiki) 1.8.1 e versioni precedenti consentono aggressori remoti di inserire lo script Web arbitrario o HTML tramite via (1) il parametro tema tiki-switch_theme.php, (2) trovare e parametri prioritari per messu-mailbox.php, (3) flag, priorità, flagval, sort_mode, o trovare parametri messu-read.php, (4) articleId parametro tiki-read_article.php, (5) parentId parametro tiki-browse_categories.php, (6) comments_threshold parametro tiki-index.php (7) articleId parametro tiki-print_article.php, (8) galleryId parametro tiki-list_file_gallery.php, (9) galleryId parametro tiki-upload_file .php, (10) faqid parametro tiki-view_faq.php, (11) chartId parametro tiki-view_chart.php, o (12) surveyId parametro tiki-survey_stats_survey.php. |
http://www.securityfocus.com/bid/10100 http://marc.info/?l=bugtraq&m=108180073206947&w=2 http://tikiwiki.org/tiki-read_article.php?articleId=66 http://secunia.com/advisories/11344 https://exchange.xforce.ibmcloud.com/vulnerabilities/15846 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1924 |
Vulnerabilità: CVE-2004-1924
