~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
PublicDate: 2007-10-26
Candidate: CVE-2007-5684
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5684
Description:
 Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and
 earlier allow remote attackers to include and execute arbitrary files via
 an absolute pathname in (1) error_handler_file and (2) local_php parameters
 to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the imp_language
 parameter to tiki-imexport_languages.php.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Assigned-to:
dapper_tikiwiki: DNE
edgy_tikiwiki: DNE
feisty_tikiwiki: needed (reached end-of-life)
gutsy_tikiwiki: needed (reached end-of-life)
hardy_tikiwiki: DNE
intrepid_tikiwiki: DNE
devel_tikiwiki: DNE
upstream_tikiwiki: