CVE-2007-6526: XSS
Published Dec 27, 2007
·Updated
Cross-site scripting (XSS) vulnerability in tiki-specialchars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the areaname parameter.
Affected Software
13 affected components
Tiki Wiki CMS Groupware=1.9.4
Tiki Wiki CMS Groupware<=1.9.8
Tiki Wiki CMS Groupware=1.9.0-rc2
Tiki Wiki CMS Groupware=1.9.3
Tiki Wiki CMS Groupware=1.9.0
Tiki Wiki CMS Groupware=1.6.1
Tiki Wiki CMS Groupware=1.9.5
Tiki Wiki CMS Groupware=1.9.0-rc1
Tiki Wiki CMS Groupware=1.9.0-rc3
Tiki Wiki CMS Groupware=1.9.6
Tiki Wiki CMS Groupware=1.9.2
Tiki Wiki CMS Groupware=1.9.1
Tiki Wiki CMS Groupware=1.9.7
Remediation
Patch Available
Event History
Dec 27, 2007
CVE Published
10:46 PM
Dec 28, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6526?
CVE-2007-6526 has a medium severity rating due to its potential for allowing cross-site scripting attacks.
2
How do I fix CVE-2007-6526?
To fix CVE-2007-6526, upgrade to TikiWiki version 1.9.9 or later where the vulnerability has been addressed.
3
What software versions are affected by CVE-2007-6526?
CVE-2007-6526 affects TikiWiki versions from 1.6.1 to 1.9.8, including specific release candidates.
4
Can CVE-2007-6526 be exploited remotely?
Yes, CVE-2007-6526 can be exploited remotely by attackers injecting arbitrary web scripts through the area_name parameter.
5
What are the potential impacts of CVE-2007-6526?
The impacts of CVE-2007-6526 include unauthorized access to user sessions and potential data theft or manipulation.