TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
BID:12328
Info
TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
| Bugtraq ID: | 12328 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2005 12:00AM |
| Updated: | Jan 21 2005 12:00AM |
| Credit: | These vulnerabilities were announced by the vendor. |
| Vulnerable: |
TikiWiki Project TikiWiki 1.9 -rc3.1 TikiWiki Project TikiWiki 1.9 -rc3 TikiWiki Project TikiWiki 1.9 -rc2 TikiWiki Project TikiWiki 1.9 -rc1 TikiWiki Project TikiWiki 1.8.5 TikiWiki Project TikiWiki 1.8.4 TikiWiki Project TikiWiki 1.8.3 TikiWiki Project TikiWiki 1.8.2 TikiWiki Project TikiWiki 1.8.1 TikiWiki Project TikiWiki 1.8 TikiWiki Project TikiWiki 1.7.9 TikiWiki Project TikiWiki 1.7.8 TikiWiki Project TikiWiki 1.7.7 TikiWiki Project TikiWiki 1.7.6 TikiWiki Project TikiWiki 1.7.5 TikiWiki Project TikiWiki 1.7.4 TikiWiki Project TikiWiki 1.7.3 TikiWiki Project TikiWiki 1.7.2 TikiWiki Project TikiWiki 1.7.1 .1 |
| Not Vulnerable: | |
Discussion
TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
TikiWiki is reported prone to multiple unspecified vulnerabilities that may result in a remote attacker executing arbitrary PHP script code in the context of the hosting web server process.
It is reported that these vulnerabilities will allow a remote attacker to write an arbitrary PHP script file into the TikiWiki temporary folder. Once the file has been written the attacker may directly request the file.
This BID will be updated as soon as further details regarding these vulnerabilities is made available.
TikiWiki is reported prone to multiple unspecified vulnerabilities that may result in a remote attacker executing arbitrary PHP script code in the context of the hosting web server process.
It is reported that these vulnerabilities will allow a remote attacker to write an arbitrary PHP script file into the TikiWiki temporary folder. Once the file has been written the attacker may directly request the file.
This BID will be updated as soon as further details regarding these vulnerabilities is made available.
Exploit / POC
TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
It is reported that exploits to leverage these vulnerabilities are circulating in the wild.
It is reported that exploits to leverage these vulnerabilities are circulating in the wild.
Solution / Fix
TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
Solution:
The vendor has released fixes to address these vulnerabilities. If customers are running TikiWiki 1.8.x they are advised to CVS update to BRANCH-1-8, if customers are running any version of 1.9 they are advised to CVS update CVS BRANCH-1-9. Customers running TikiWiki version 1.7.x are advised to upgrade to 1.8. Additionally, access controls will need to be set in place; customers should peruse the referenced security alert for further information.
Gentoo has released advisory GLSA 200501-41 to address these issues. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/tikiwiki-1.8.5"
Please see the referenced Gentoo advisory for more information.
TikiWiki Project TikiWiki 1.8
TikiWiki Project TikiWiki 1.8.1
TikiWiki Project TikiWiki 1.8.2
TikiWiki Project TikiWiki 1.8.3
TikiWiki Project TikiWiki 1.8.4
TikiWiki Project TikiWiki 1.8.5
TikiWiki Project TikiWiki 1.9 -rc3
TikiWiki Project TikiWiki 1.9 -rc3.1
TikiWiki Project TikiWiki 1.9 -rc2
TikiWiki Project TikiWiki 1.9 -rc1
Solution:
The vendor has released fixes to address these vulnerabilities. If customers are running TikiWiki 1.8.x they are advised to CVS update to BRANCH-1-8, if customers are running any version of 1.9 they are advised to CVS update CVS BRANCH-1-9. Customers running TikiWiki version 1.7.x are advised to upgrade to 1.8. Additionally, access controls will need to be set in place; customers should peruse the referenced security alert for further information.
Gentoo has released advisory GLSA 200501-41 to address these issues. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/tikiwiki-1.8.5"
Please see the referenced Gentoo advisory for more information.
TikiWiki Project TikiWiki 1.8
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.8.1
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.8.2
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.8.3
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.8.4
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.8.5
-
TikiWiki Project lastiki_BRANCH-1-8.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-8.tar.bz2
TikiWiki Project TikiWiki 1.9 -rc3
-
TikiWiki Project lastiki_BRANCH-1-9.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-9.tar.bz2
TikiWiki Project TikiWiki 1.9 -rc3.1
-
TikiWiki Project lastiki_BRANCH-1-9.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-9.tar.bz2
TikiWiki Project TikiWiki 1.9 -rc2
-
TikiWiki Project lastiki_BRANCH-1-9.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-9.tar.bz2
TikiWiki Project TikiWiki 1.9 -rc1
-
TikiWiki Project lastiki_BRANCH-1-9.tar.bz2
http://de.tikiwiki.org/tar/lastiki_BRANCH-1-9.tar.bz2
References
TikiWiki Multiple Remote Unspecified PHP Script Code Execution Vulnerabilities
References:
References:
- January Security Alert (TikiWiki Project)
- TikiWiki Homepage (TikiWiki Project)