CVE-2004-1926: Code Injection
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1926?
CVE-2004-1926 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2004-1926?
To fix CVE-2004-1926, upgrade Tiki CMS/Groupware to version 1.8.2 or later.
What versions of Tiki CMS/Groupware are affected by CVE-2004-1926?
CVE-2004-1926 affects Tiki CMS/Groupware versions 1.6.1 through 1.8.1.
What types of attacks are possible with CVE-2004-1926?
CVE-2004-1926 allows remote attackers to inject arbitrary code through various user profile fields and site directory fields.
Is CVE-2004-1926 a remote code execution vulnerability?
Yes, CVE-2004-1926 is a remote code execution vulnerability that can be exploited by attackers.