Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Gentoo: GLSA-200507-07 Urgent: TikiWiki Remote Code Execution Issue

gentoo
Calendar Grey July 6, 2005
Scroller Gentoo
The Gentoo GLSA 200802-02 identifies a severe vulnerability in WordPress, enabling unauthorized access to sensitive data through insecure file permissions.
TikiWiki includes PHP XML-RPC code, making it vulnerable to arbitrary command execution.

Summary

Gentoo Linux Security Advisory GLSA 200507-06 https://security.gentoo.org/ Severity: High Title: TikiWiki: Arbitrary command execution through XML-RPC Date: July 06, 2005 Bugs: #97648 ID: 200507-06

Synopsis ======= TikiWiki includes PHP XML-RPC code, making it vulnerable to arbitrary command execution.
Background ========= TikiWiki is a web-based groupware and content management system (CMS), using PHP, ADOdb and Smarty. TikiWiki includes vulnerable PHP XML-RPC code.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/tikiwiki < 1.8.5-r1 >= 1.8.5-r1
========== TikiWiki is vulnerable to arbitrary command execution as described in GLSA 200507-01.
Impa...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround