Vulnerabilities
Vulnerable Software
Tiki:  >> Tiki  Security Vulnerabilities
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
CVSS Score
7.2
EPSS Score
0.034
Published
2020-01-27
Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-11-20
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-11-20
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-02-21
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
CVSS Score
8.8
EPSS Score
0.005
Published
2018-02-21


Contact Us

Shodan ® - All rights reserved