CVE-2006-6168: Input Validation
tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6168?
CVE-2006-6168 is classified as a moderate severity vulnerability due to its potential for notification-spam through email spoofing.
How do I fix CVE-2006-6168?
To fix CVE-2006-6168, upgrade to TikiWiki version 1.9.7 or later, which implements proper email validation checks.
What versions of TikiWiki are affected by CVE-2006-6168?
CVE-2006-6168 affects TikiWiki versions from 1.6.1 up to 1.9.6.
Can exploitation of CVE-2006-6168 lead to security risks?
Yes, exploitation of CVE-2006-6168 can lead to notification-spam and potential abuse of the email notification system.
Is CVE-2006-6168 a remote vulnerability?
Yes, CVE-2006-6168 is a remote vulnerability that allows attackers to send malicious emails without authentication.