CVE-2007-5684: Path Traversal
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) errorhandlerfile and (2) localphp parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the implanguage parameter to tiki-imexportlanguages.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5684?
CVE-2007-5684 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2007-5684?
To fix CVE-2007-5684, upgrade TikiWiki to the latest version that has addressed this directory traversal vulnerability.
Which versions of TikiWiki are affected by CVE-2007-5684?
CVE-2007-5684 affects TikiWiki versions 1.9.8.1 and earlier.
Can CVE-2007-5684 lead to data loss?
Yes, due to its ability to execute arbitrary files, CVE-2007-5684 can potentially lead to data loss.
How can an attacker exploit CVE-2007-5684?
An attacker can exploit CVE-2007-5684 by sending crafted requests with specific parameters to the affected TikiWiki installation.