Tiki Wiki CMS Groupware是Tiki软件社区的一套开源的内容管理和门户应用程序,它可用于创建Web应用程序、门户网站、企业内部网、外联网等。。 Tiki Wiki CMS Groupware 8.3版本中的tiki-featured_link.php中存在URI重定向漏洞,该漏洞源于应用程序对用户提供的输入未经充分过滤。攻击成功可能导致钓鱼攻击,也可能执行其他的攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | TikiWiki CMS Groupware v8.3 - Open Redirect | https://github.com/Cappricio-Securities/CVE-2012-5321 | POC Details |
| 2 | tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2012/CVE-2012-5321.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2012-5323 | Xavi 跨站请求伪造漏洞 | |
| CVE-2012-5328 | WordPress Mingle Forum插件多个SQL注入漏洞 | |
| CVE-2012-5331 | asaanCart 路径遍历漏洞 | |
| CVE-2012-5332 | at32 Reverse Proxy 拒绝服务漏洞 | |
| CVE-2012-5333 | Pre Printing Press SQL注入漏洞 | |
| CVE-2012-5334 | Pre Printing Press ‘pid’ 参数SQL注入漏洞 | |
| CVE-2012-5335 | Tiny Server 路径遍历漏洞 | |
| CVE-2012-5330 | asaanCart 多个跨站脚本漏洞 | |
| CVE-2012-5324 | Tracker Software PDF-XChange缓冲区溢出漏洞 | |
| CVE-2012-0846 | Craig Knudsen WebCalendar ‘location’跨站脚本漏洞 | |
| CVE-2012-5325 | WordPress ‘Shortcode Redirect’ 插件 ‘domain’ 参数多个跨站脚本漏洞 | |
| CVE-2012-5322 | Xavi 7968 ADSL Router 多个跨站脚本漏洞 | |
| CVE-2012-5320 | Sagem 跨站请求伪造漏洞 | |
| CVE-2012-5319 | D-Link 跨站请求伪造漏洞 | |
| CVE-2012-1416 | SocialCMS 多个跨站请求伪造漏洞 | |
| CVE-2012-1308 | D-Link DSL-2640B ‘redpass.cgi’ 跨站请求伪造漏洞 | |
| CVE-2012-1189 | Open Racing Car Simulator/Speed Dreams 基于栈的缓冲区溢出漏洞 | |
| CVE-2011-5208 | WordPress BackWPup插件多个路径遍历漏洞 | |
| CVE-2011-4929 | Redmine 未明安全漏洞 | |
| CVE-2011-4928 | Redmine 跨站脚本漏洞 |
Showing top 20 of 50 CVEs. View all on vendor page → →
No comments yet