Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tiki 安全漏洞
Vulnerability Description
Tiki是Tiki软件社区的一套开源的内容管理和门户应用程序,它可用于创建Web应用程序、门户网站、企业内部网、外联网等。 Tiki 17.1版本中存在安全漏洞,该漏洞源于程序没有检测用户输入的特殊字符。攻击者可利用该漏洞打开虚拟机上的CMD.EXE或Calculator窗口,执行恶意操作。
CVSS Information
N/A
Vulnerability Type
N/A