CVE-2004-1927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/04/2004
Last modified:
03/04/2025

Description

Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:*:*:*:*:*:*:*:* 1.8.1 (including)
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:1.6.1:*:*:*:*:*:*:*