|
TikiWiki Tiki-Graph_Formula.PHP White-List Check Code Injection Vulnerability
TikiWiki is prone to a remote PHP code-injection vulnerability because the application fails to sufficiently sanitize user-supplied input. An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. TikiWiki 1.9.8.1 and prior versions are vulnerable. |
|
Privacy Statement |