CVE-2006-6457: Infoleak
tiki-wikirss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6457?
CVE-2006-6457 is considered a high-severity vulnerability due to the potential exposure of sensitive MySQL credentials.
How do I fix CVE-2006-6457?
To fix CVE-2006-6457, update to a patched version of Tikiwiki that addresses this vulnerability, preferably a release later than 1.9.5.
What systems are affected by CVE-2006-6457?
CVE-2006-6457 affects Tikiwiki versions 1.9.2 and 1.9.5, and possibly other versions.
What type of attack does CVE-2006-6457 allow?
CVE-2006-6457 allows remote attackers to exploit the vulnerability by obtaining sensitive information through crafted input.
What information can be leaked through CVE-2006-6457?
CVE-2006-6457 can leak sensitive information such as MySQL username and password through error messages.