CVE-2004-1386: Input Validation
Published Dec 31, 2004
·Updated
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.
Affected Software
1 affected component
Tiki Wiki CMS Groupware<=1.6.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1386?
CVE-2004-1386 is rated as high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2004-1386?
To fix CVE-2004-1386, upgrade TikiWiki to version 1.8.4.1 or later.
3
What systems are affected by CVE-2004-1386?
CVE-2004-1386 affects TikiWiki versions before 1.8.4.1, specifically those prior to version 1.6.1.
4
What type of attacks can CVE-2004-1386 facilitate?
CVE-2004-1386 can facilitate remote attackers to upload and execute arbitrary PHP scripts.
5
Is CVE-2004-1386 fixed in TikiWiki version 1.8.4.1?
Yes, CVE-2004-1386 is fixed in TikiWiki version 1.8.4.1 and later.