Vulnerabilities
Vulnerable Software
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
CVSS Score
4.3
EPSS Score
0.038
Published
2012-10-01
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
CVSS Score
5.0
EPSS Score
0.172
Published
2012-07-12


Contact Us

Shodan ® - All rights reserved