CVE-2005-0200

critical

Description

TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.

References

http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml

http://tikiwiki.org/art102

http://secunia.com/advisories/13948

Details

Source: Mitre, NVD

Published: 2005-05-02

Updated: 2012-10-24

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical