Lucene search

K
cveMitreCVE-2005-1925
HistoryNov 18, 2005 - 11:00 a.m.

CVE-2005-1925

2005-11-1811:00:00
CWE-22
mitre
web.nvd.nist.gov
22
cve
2005
1925
tikiwiki
directory traversal
vulnerabilities
remote attackers
arbitrary files
execute commands
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.014

Percentile

86.2%

Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.

Affected configurations

Nvd
Node
tikitikiwiki_cms\/groupwareRange1.9.0
OR
tikitikiwiki_cms\/groupwareMatch1.6.1
OR
tikitikiwiki_cms\/groupwareMatch1.9.0rc1
OR
tikitikiwiki_cms\/groupwareMatch1.9.0rc2
OR
tikitikiwiki_cms\/groupwareMatch1.9.0rc3
VendorProductVersionCPE
tikitikiwiki_cms\/groupware*cpe:2.3:a:tiki:tikiwiki_cms\/groupware:*:*:*:*:*:*:*:*
tikitikiwiki_cms\/groupware1.6.1cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.6.1:*:*:*:*:*:*:*
tikitikiwiki_cms\/groupware1.9.0cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.0:rc1:*:*:*:*:*:*
tikitikiwiki_cms\/groupware1.9.0cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.0:rc2:*:*:*:*:*:*
tikitikiwiki_cms\/groupware1.9.0cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.9.0:rc3:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.014

Percentile

86.2%

Related for CVE-2005-1925