Back
CVE-2004-1386
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CWE-20
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| tiki | tikiwiki_cms\/groupware | * |
GitHub Security Advisory GHSA-9hvw-hh93-8939
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote...
References (14)
- http://securitytracker.com/id?1012700
- http://tikiwiki.org/tiki-read_article.php?articleId=97 Patch
- http://www.ciac.org/ciac/bulletins/p-084.shtml
- http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml Patch
- http://www.osvdb.org/12628
- http://www.securityfocus.com/bid/12110 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18691
- http://securitytracker.com/id?1012700
- http://tikiwiki.org/tiki-read_article.php?articleId=97 Patch
- http://www.ciac.org/ciac/bulletins/p-084.shtml
- http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml Patch
- http://www.osvdb.org/12628
- http://www.securityfocus.com/bid/12110 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18691
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.81%
Top 23% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub