CVE-2004-1927: Path Traversal
Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1927?
CVE-2004-1927 is considered medium severity due to its potential to expose sensitive file information through directory traversal.
How do I fix CVE-2004-1927?
To fix CVE-2004-1927, upgrade to a version of Tiki CMS/Groupware that is newer than 1.8.1.
What software versions are affected by CVE-2004-1927?
CVE-2004-1927 affects Tiki CMS/Groupware versions 1.6.1 and earlier up to version 1.8.1.
What is a directory traversal vulnerability in CVE-2004-1927?
A directory traversal vulnerability in CVE-2004-1927 allows attackers to access files outside the intended directory structure using .. (dot dot) sequences.
Can CVE-2004-1927 be exploited remotely?
Yes, CVE-2004-1927 can be exploited remotely, making it a significant risk for exposed Tiki CMS/Groupware installations.