Tiki-Wiki CMS Calendar Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 23 Jun 2016.

  1. Packet Storm

    Packet Storm Guest

    Tiki-Wiki CMS's calendar module contains a remote code execution vulnerability within the viewmode GET parameter. The calendar module is NOT enabled by default. If enabled, the default permissions are set to NOT allow anonymous users to access.

    Continue reading...
     

Share This Page

Loading...