This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ikiwiki First view 2008-04-21
Product Ikiwiki Last view 2019-11-21
Version 1.50 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:ikiwiki:ikiwiki

Activity : Overall

Related : CVE

  Date Alert Description
6.1 2019-11-21 CVE-2015-2793

Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.

6.1 2019-10-30 CVE-2010-1673

A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

8.2 2019-10-29 CVE-2011-1408

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

6.1 2019-10-29 CVE-2011-0428

Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments.

7.5 2019-06-05 CVE-2019-9187

ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.

9.8 2018-04-13 CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

5.3 2018-04-13 CVE-2016-9646

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.

6.5 2018-04-10 CVE-2016-9645

The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.

6.1 2016-05-10 CVE-2016-4561

Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message.

4.3 2012-05-29 CVE-2012-0220

Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.

3.5 2011-04-11 CVE-2011-1401

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

5 2009-08-31 CVE-2009-2944

Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.

4.3 2008-04-21 CVE-2008-0165

Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.

CWE : Common Weakness Enumeration

%idName
54% (6) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
18% (2) CWE-287 Improper Authentication
9% (1) CWE-352 Cross-Site Request Forgery (CSRF)
9% (1) CWE-284 Access Control (Authorization) Issues
9% (1) CWE-59 Improper Link Resolution Before File Access ('Link Following')

Open Source Vulnerability Database (OSVDB)

id Description
71838 ikiwiki meta stylesheet XSS
57575 teximg Plugin for ikiwiki TEX Command Arbitrary File Local Disclosure
44657 ikiwiki User Preferences Multiple Form CSRF

OpenVAS Exploits

id Description
2012-08-30 Name : Fedora Update for ikiwiki FEDORA-2012-7976
File : nvt/gb_fedora_2012_7976_ikiwiki_fc17.nasl
2012-05-31 Name : Debian Security Advisory DSA 2474-1 (ikiwiki)
File : nvt/deb_2474_1.nasl
2012-05-28 Name : Fedora Update for ikiwiki FEDORA-2012-8161
File : nvt/gb_fedora_2012_8161_ikiwiki_fc15.nasl
2012-05-28 Name : Fedora Update for ikiwiki FEDORA-2012-8151
File : nvt/gb_fedora_2012_8151_ikiwiki_fc16.nasl
2011-08-03 Name : FreeBSD Ports: ikiwiki
File : nvt/freebsd_ikiwiki5.nasl
2011-05-12 Name : Debian Security Advisory DSA 2214-1 (ikiwiki)
File : nvt/deb_2214_1.nasl
2011-04-22 Name : Fedora Update for ikiwiki FEDORA-2011-5173
File : nvt/gb_fedora_2011_5173_ikiwiki_fc13.nasl
2011-04-22 Name : Fedora Update for ikiwiki FEDORA-2011-5180
File : nvt/gb_fedora_2011_5180_ikiwiki_fc14.nasl
2010-04-06 Name : Fedora Update for ikiwiki FEDORA-2010-4933
File : nvt/gb_fedora_2010_4933_ikiwiki_fc11.nasl
2009-09-15 Name : Fedora Core 11 FEDORA-2009-9244 (ikiwiki)
File : nvt/fcore_2009_9244.nasl
2009-09-15 Name : Fedora Core 10 FEDORA-2009-9254 (ikiwiki)
File : nvt/fcore_2009_9254.nasl
2009-09-15 Name : FreeBSD Ports: ikiwiki
File : nvt/freebsd_ikiwiki4.nasl
2009-09-03 Name : ikiwiki Teximg Plugin TeX Command Arbitrary File Disclosure Vulnerability
File : nvt/gb_ikiwiki_teximg_info_disclosure_vuln.nasl
2009-09-02 Name : Debian Security Advisory DSA 1875-1 (ikiwiki)
File : nvt/deb_1875_1.nasl
2008-09-04 Name : FreeBSD Ports: ikiwiki
File : nvt/freebsd_ikiwiki1.nasl
2008-06-11 Name : Debian Security Advisory DSA 1553-2 (ikiwiki)
File : nvt/deb_1553_2.nasl
2008-04-21 Name : Debian Security Advisory DSA 1553-1 (ikiwiki)
File : nvt/deb_1553_1.nasl

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2017-03-06 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_7b35a77a015111e7ae1b002590263bf5.nasl - Type: ACT_GATHER_INFO
2017-03-06 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_5ed094a0015011e7ae1b002590263bf5.nasl - Type: ACT_GATHER_INFO
2017-02-01 Name: The remote Debian host is missing a security update.
File: debian_DLA-812.nasl - Type: ACT_GATHER_INFO
2017-01-31 Name: The remote Fedora host is missing a security update.
File: fedora_2017-8873ebdb43.nasl - Type: ACT_GATHER_INFO
2017-01-30 Name: The remote Fedora host is missing a security update.
File: fedora_2017-c756d37779.nasl - Type: ACT_GATHER_INFO
2017-01-13 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3760.nasl - Type: ACT_GATHER_INFO
2016-06-06 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_0297b2602b3b11e6ae88002590263bf5.nasl - Type: ACT_GATHER_INFO
2016-05-11 Name: The remote Debian host is missing a security update.
File: debian_DLA-463.nasl - Type: ACT_GATHER_INFO
2016-05-11 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3571.nasl - Type: ACT_GATHER_INFO
2015-05-04 Name: The remote Fedora host is missing a security update.
File: fedora_2015-6759.nasl - Type: ACT_GATHER_INFO
2015-05-04 Name: The remote Fedora host is missing a security update.
File: fedora_2015-6806.nasl - Type: ACT_GATHER_INFO
2015-05-04 Name: The remote Fedora host is missing a security update.
File: fedora_2015-6815.nasl - Type: ACT_GATHER_INFO
2012-05-29 Name: The remote Fedora host is missing a security update.
File: fedora_2012-7976.nasl - Type: ACT_GATHER_INFO
2012-05-29 Name: The remote Fedora host is missing a security update.
File: fedora_2012-8151.nasl - Type: ACT_GATHER_INFO
2012-05-29 Name: The remote Fedora host is missing a security update.
File: fedora_2012-8161.nasl - Type: ACT_GATHER_INFO
2012-05-18 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2474.nasl - Type: ACT_GATHER_INFO
2011-06-16 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_3145faf1974c11e0869e000c29249b2e.nasl - Type: ACT_GATHER_INFO
2011-04-22 Name: The remote Fedora host is missing a security update.
File: fedora_2011-5173.nasl - Type: ACT_GATHER_INFO
2011-04-22 Name: The remote Fedora host is missing a security update.
File: fedora_2011-5180.nasl - Type: ACT_GATHER_INFO
2011-04-18 Name: The remote Fedora host is missing a security update.
File: fedora_2011-5249.nasl - Type: ACT_GATHER_INFO
2011-04-11 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2214.nasl - Type: ACT_GATHER_INFO
2010-02-24 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1875.nasl - Type: ACT_GATHER_INFO
2009-09-14 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_6e8f54afa07d11dea649000c2955660f.nasl - Type: ACT_GATHER_INFO
2009-09-14 Name: The remote Fedora host is missing a security update.
File: fedora_2009-9254.nasl - Type: ACT_GATHER_INFO
2009-09-14 Name: The remote Fedora host is missing a security update.
File: fedora_2009-9244.nasl - Type: ACT_GATHER_INFO