CVE-2004-1926 Information
Feb 14, 2021
cve
Description
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme (2) Country (3) Real Name or (4) Displayed time zone fields in a User Profile or the (5) Name (6) Description (7) URL or (8) Country fields in a Directory/Add Site operation.
Reference
http://marc.info/?l=bugtraq&m=108180073206947&w=2 http://secunia.com/advisories/11344 http://tikiwiki.org/tiki-read_article.php?articleId=66 http://www.securityfocus.com/bid/10100
Share on: