Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance News & Announcements
  • Search

[ GLSA 200507-06 ] TikiWiki: Arbitrary command execution through XML-RPC

Read this before submitting your first post to any forum
Post Reply
Advanced search
1 post • Page 1 of 1
Author
Message
GLSA
Advocate
Advocate
Posts: 2663
Joined: Wed May 12, 2004 4:41 pm

[ GLSA 200507-06 ] TikiWiki: Arbitrary command execution thr

  • Quote

Post by GLSA » Wed Jul 06, 2005 8:51 pm

Gentoo Linux Security Advisory

Title: TikiWiki: Arbitrary command execution through XML-RPC ([glsa=200507-06]GLSA 200507-06[/glsa])
Severity: high
Exploitable: remote
Date: July 06, 2005
Bug(s): #97648
ID: 200507-06

Synopsis

TikiWiki includes PHP XML-RPC code, making it vulnerable to arbitrary command execution.

Background

TikiWiki is a web-based groupware and content management system (CMS), using PHP, ADOdb and Smarty. TikiWiki includes vulnerable PHP XML-RPC code.

Affected Packages

Package: www-apps/tikiwiki
Vulnerable: < 1.8.5-r1
Unaffected: >= 1.8.5-r1
Architectures: All supported architectures


Description

TikiWiki is vulnerable to arbitrary command execution as described in GLSA 200507-01.

Impact

A remote attacker could exploit this vulnerability to execute arbitrary PHP code by sending specially crafted XML data.

Workaround

There is no known workaround at this time.

Resolution

All TikiWiki users should upgrade to the latest version:

Code: Select all

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/tikiwiki-1.8.5-r1"


References

GLSA 200507-01
CAN-2005-1921
Last edited by GLSA on Sun May 07, 2006 4:57 pm, edited 1 time in total.
Top
Post Reply
1 post • Page 1 of 1

Return to “News & Announcements”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Authors
Gentoo is a trademark of the Gentoo Foundation, Inc. and of Förderverein Gentoo e.V.
The contents of this document, unless otherwise expressly stated, are licensed under the CC-BY-SA-4.0 license.
The Gentoo Name and Logo Usage Guidelines apply.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy