NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 64729 | CVE-2006-6168 | tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email." | 2 | 7.5 | High | 2016-12-20 | 2012-10-24 | View | |
| 57488 | CVE-2007-5423 | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | 2 | 7.5 | High | 2017-01-07 | 2012-10-24 | View | |
| 46517 | CVE-2012-5321 | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection." | 2 | 5.8 | Medium | 2017-01-19 | 2012-10-09 | View | |
| 72304 | CVE-2004-1926 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
| 72301 | CVE-2004-1923 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2514 of 17672, showing 5 records out of 88360 total, starting on record 12566, ending on 12570