Tiki-Wiki CMS Calendar Command Execution
Posted by deepcore on June 23, 2016 – 11:57 pm
Tiki-Wiki CMS’s calendar module contains a remote code execution vulnerability within the viewmode GET parameter. The calendar module is NOT enabled by default. If enabled, the default permissions are set to NOT allow anonymous users to access.
Post a reply
You must be logged in to post a comment.