CVE-2004-1923: Infoleak
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) bannerclick.php, (2) categorize.php, (3) tiki-adminincludedirectory.php, (4) tiki-directorysearch.php, which reveal the web server path in an error message.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1923?
CVE-2004-1923 is classified as a medium severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2004-1923?
To fix CVE-2004-1923, upgrade your Tiki CMS/Groupware to version 1.8.2 or later.
What types of information can be revealed by CVE-2004-1923?
CVE-2004-1923 can reveal sensitive information including the web server path in error messages.
Which versions of Tiki CMS/Groupware are affected by CVE-2004-1923?
Versions of Tiki CMS/Groupware up to and including 1.8.1 are affected by CVE-2004-1923.
Can CVE-2004-1923 be exploited remotely?
Yes, CVE-2004-1923 can be exploited by remote attackers via direct requests to specific PHP scripts.