CVE-2005-3529: Infoleak
Published Nov 20, 2005
·Updated
tiki-viewforumthread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topicssortmode parameter, possibly related to an SQL injection vulnerability.
Affected Software
3 affected components
Tiki Wiki CMS Groupware=1.9.0
Tiki Wiki CMS Groupware=1.9.1
Tiki Wiki CMS Groupware=1.9.2
Event History
Nov 20, 2005
CVE Published
10:03 PM
Nov 21, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3529?
CVE-2005-3529 is classified as a medium severity vulnerability.
2
How can I fix CVE-2005-3529?
To fix CVE-2005-3529, upgrade TikiWiki to version 1.9.3 or later.
3
What does CVE-2005-3529 exploit?
CVE-2005-3529 exploits an invalid topics_sort_mode parameter to leak the installation path.
4
Which TikiWiki versions are affected by CVE-2005-3529?
CVE-2005-3529 affects TikiWiki versions 1.9.0, 1.9.1, and 1.9.2.
5
Is CVE-2005-3529 related to SQL injection?
Yes, CVE-2005-3529 is possibly related to an SQL injection vulnerability.