Lucene search

K
cvelistDebianCVELIST:CVE-2016-9646
HistoryApr 13, 2018 - 3:00 p.m.

CVE-2016-9646 Commit metadata forgery via CGI::FormBuilder context-dependent APIs

2018-04-1315:00:00
debian
www.cve.org
7

AI Score

7.2

Confidence

Low

EPSS

0.012

Percentile

85.3%

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla’s CVE-2014-1572), which can be abused to lead to commit metadata forgery.

CNA Affected

[
  {
    "product": "ikiwiki",
    "vendor": "ikiwiki",
    "versions": [
      {
        "status": "affected",
        "version": "before 3.20161229"
      }
    ]
  }
]