4.3
CVSSv2

CVE-2011-4551

Published: 01/10/2012 Updated: 24/10/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware prior to 8.2 and LTS prior to 6.5 allows remote malicious users to inject arbitrary web script or HTML via arbitrary parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

tiki tikiwiki cms\\/groupware 7.2

tiki tikiwiki cms\\/groupware 6.1

tiki tikiwiki cms\\/groupware 4.1

tiki tikiwiki cms\\/groupware 4

tiki tikiwiki cms\\/groupware 3.5

tiki tikiwiki cms\\/groupware 2.2

tiki tikiwiki cms\\/groupware

tiki tikiwiki cms\\/groupware 8.0

tiki tikiwiki cms\\/groupware 7.0

tiki tikiwiki cms\\/groupware 3.1

tiki tikiwiki cms\\/groupware 3.0

tiki tikiwiki cms\\/groupware 3.3

tiki tikiwiki cms\\/groupware 3.2

tiki tikiwiki cms\\/groupware 5.1

tiki tikiwiki cms\\/groupware 5.0

tiki tikiwiki cms\\/groupware 5.2

tiki tikiwiki cms\\/groupware 5.3

tiki tikiwiki cms\\/groupware 7.1

tiki tikiwiki cms\\/groupware 6.0

tiki tikiwiki cms\\/groupware 6.2

tiki tikiwiki cms\\/groupware 4.2

tiki tikiwiki cms\\/groupware 4.0

tiki tikiwiki cms\\/groupware 3.4

Exploits

source: wwwsecurityfocuscom/bid/51128/info Tiki Wiki CMS Groupware is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to st ...
Tiki Wiki CMS Groupware versions 81 and 64 LTS suffer from a stored cross site scripting vulnerability ...