CVE-2010-1134: SQL Injection
SQL injection vulnerability in the find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1134?
CVE-2010-1134 is considered a high severity vulnerability due to its potential for remote SQL injection, which can lead to significant data breaches.
How do I fix CVE-2010-1134?
To fix CVE-2010-1134, upgrade TikiWiki CMS/Groupware to version 3.5 or later, which contains the security patch.
What versions of TikiWiki are affected by CVE-2010-1134?
CVE-2010-1134 affects TikiWiki CMS/Groupware versions 3.0 through 3.4.
Can CVE-2010-1134 be exploited remotely?
Yes, CVE-2010-1134 can be exploited remotely using specially crafted requests to the vulnerable software.
What impact does CVE-2010-1134 have on affected systems?
The impact of CVE-2010-1134 can include unauthorized access to the database, data manipulation, and complete control over affected systems.