Total vulnerabilities in the database
tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability.
Software | From | Fixed in |
---|---|---|
tiki / tikiwiki_cms/groupware | 1.9.0 | 1.9.0.x |
tiki / tikiwiki_cms/groupware | 1.9.2 | 1.9.2.x |
tiki / tikiwiki_cms/groupware | 1.9.1 | 1.9.1.x |