NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
64729  CVE-2006-6168  tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email."    7.5  High  2016-12-20  2012-10-24  View
57488  CVE-2007-5423  tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.    7.5  High  2017-01-07  2012-10-24  View
46517  CVE-2012-5321  tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."    5.8  Medium  2017-01-19  2012-10-09  View
72304  CVE-2004-1926  Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.    7.5  High  2016-12-20  2016-10-17  View
72301  CVE-2004-1923  Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.    Medium  2017-07-18  2017-07-10  View

Page 2514 of 17672, showing 5 records out of 88360 total, starting on record 12566, ending on 12570

Actions