CVE-2008-3654: Medium severity tiki wiki cms groupware vulnerability
Published Aug 13, 2008
·Updated
Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors.
Affected Software
15 affected components
Tiki Wiki CMS Groupware=1.9.4
Tiki Wiki CMS Groupware=1.9.0-rc2
Tiki Wiki CMS Groupware=1.9.3
Tiki Wiki CMS Groupware=1.9.0
Tiki Wiki CMS Groupware=1.6.1
Tiki Wiki CMS Groupware=1.9.5
Tiki Wiki CMS Groupware<=1.9.9
Tiki Wiki CMS Groupware=1.9.0-rc1
Tiki Wiki CMS Groupware=1.9.8
Tiki Wiki CMS Groupware=1.9.0-rc3
Tiki Wiki CMS Groupware=1.9.6
Tiki Wiki CMS Groupware=1.9.8.1
Tiki Wiki CMS Groupware=1.9.2
Tiki Wiki CMS Groupware=1.9.1
Tiki Wiki CMS Groupware=1.9.7
Event History
Aug 13, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3654?
CVE-2008-3654 is classified as a vulnerability that allows attackers to potentially obtain sensitive configuration information.
2
How do I fix CVE-2008-3654?
To fix CVE-2008-3654, upgrade TikiWiki CMS/Groupware to version 2.0 or later.
3
What versions of TikiWiki are affected by CVE-2008-3654?
CVE-2008-3654 affects TikiWiki CMS/Groupware versions prior to 2.0, including various versions in the 1.6.x and 1.9.x series.
4
What potential impact does CVE-2008-3654 have on a system?
CVE-2008-3654 could allow attackers to access sensitive information regarding the system's path and PHP configuration.
5
Is CVE-2008-3654 exploitable remotely?
Yes, CVE-2008-3654 may be engaged by an attacker through various unspecified vectors.