CVE Database
/

CVE-2012-0911

Back to search

CVE-2012-0911

Published: Jul 12, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.

VendorProductVersions

n/a

n/a

affected
n/a

References

19630
exploit
x_refsource_EXPLOIT-DB
19573
exploit
x_refsource_EXPLOIT-DB
54298
vdb-entry
x_refsource_BID
http://dev.tiki.org/item4109
x_refsource_CONFIRM
83534
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now