CVE-2012-0911: Code Injection
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-printmultipages.php or (b) tiki-printpages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-sendobjects.php, which is not properly handled when processed by the unserialize function.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0911?
The severity of CVE-2012-0911 is considered critical due to the potential for remote code execution.
How do I fix CVE-2012-0911?
To fix CVE-2012-0911, you should upgrade to TikiWiki CMS/Groupware version 6.7 LTS or later, or version 8.4 or later.
Which versions of TikiWiki are affected by CVE-2012-0911?
CVE-2012-0911 affects TikiWiki CMS/Groupware versions prior to 6.7 LTS and prior to 8.4.
What types of attacks can exploit CVE-2012-0911?
Attackers can exploit CVE-2012-0911 to execute arbitrary PHP code via crafted serialized objects.
Are there any workarounds for CVE-2012-0911?
There are no known effective workarounds for CVE-2012-0911; upgrading to a patched version is recommended.