5.8
CVSSv2

CVE-2012-5321

Published: 08/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote malicious users to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

Vulnerable Product Search on Vulmon Subscribe to Product

tiki tikiwiki cms\\/groupware 8.3

Exploits

source: wwwsecurityfocuscom/bid/52079/info Tiki Wiki CMS Groupware is prone to a URI-redirection vulnerability because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing attacks; other attacks are possible wwwexamplecom/tiki-featured_linkphp?type=f&url=wwwexam ...