Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-200501-12 High: TikiWiki Arbitrary Command Execution

gentoo
Calendar Grey January 10, 2005
Scroller Gentoo
Critical alert issued for Gentoo regarding TikiWiki facilitating unrestrained PHP command execution. Prompt updates are strongly advised.
A bug in TikiWiki allows certain users to upload and execute malicious PHP scripts.

Summary

Gentoo Linux Security Advisory GLSA 200501-12 https://security.gentoo.org/ Severity: High Title: TikiWiki: Arbitrary command execution Date: January 10, 2005 Bugs: #75568 ID: 200501-12

Synopsis ======= A bug in TikiWiki allows certain users to upload and execute malicious PHP scripts.
Background ========= TikiWiki is a web-based groupware and content management system (CMS), using PHP, ADOdb and Smarty.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/tikiwiki < 1.8.4.1 >= 1.8.4.1
========== TikiWiki lacks a check on uploaded images in the Wiki edit page.
Impact ===== A malicious user could run arbitrary commands on the server by uploading and ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround