Intrusions, site breakage, lost data
Security
To allow us time to patch the system, please report the vulnerability using the bug tracking system using the category "security" but without detailing the vulnerability so it cannot be exploited AND please contact the security squad with full details
and we'll deal with your input.
Please see http://security.tikiwiki.org
Table of contents
Open
| Rating | Subject | Priority | Report type | Version | Feature | Created | |
|---|---|---|---|---|---|---|---|
| - | Categorisation permission issue with Calendars and Trackers | 9 high | Bug: Consistency Bug: Error | 2.x | Calendar Security Trackers | 2009-02 | |
| 2/2 | Add "tiki_p_admin_structures" permission | 9 high | Feature request | 2.x 3.x | Permission Security Wiki Structure (book & table of content) | 2009-04 | |
| - | security issue: login issue | 8 | Bug: Error | 2.x | Cookie OS independence (Non-Linux, Windows/IIS, Mac, BSD) Security | 2009-03 | |
| 2/6 | RSS Calendar Security problem - anonymous users allowed access to secured calendar via RSS link | 7 | Calendar Category Group RSS Security | 2007-10 | |||
| - | No spam protection for shoutbox users | 7 | Bug: Usability | 1.9.x | Security Shoutbox | 2008-06 | |
| 1/2 | Need stronger CapCha | 7 | Feature request | 2.x | Security | 2008-06 | |
| 1/1 | User Information Page shows non-public wiki page titles | 7 | Bug: Error | 2.x 3.x | Permission Security Wiki (history, page rename, etc) | 2008-07 | |
| - | Security issue in a module | 7 | Bug: Error | 2.x | Modules Security | 2008-12 | |
| -2/-2 | Web Auth Needs Some Fine Tuning | 7 | Bug: conflict of two features (each works well independently) Bug: Usability Feature request | 3.x | Security User Administration (Registration, Login & Banning) | 2009-04 | |
| 2/2 | Banning users ( tiki-admin_banning.php ) doesn't work for me at doc.tw.o | 6 | Bug: Usability | 1.9.x | Security User Administration (Registration, Login & Banning) | 2007-06 | |
| 2/4 | Registration Page does not display and password suggestion does not consider security settings. | 6 | Bug: Usability Feature request | 1.9.x | Security User Administration (Registration, Login & Banning) | 2008-01 | |
| - | Setting admin password in the installer, with option to force change at first login | 6 | Feature request | 4.x | Installer (profiles, upgrades and server-related issues) Security TRIM | 2009-05 | |
| - | Warning: is_dir(): Stat failed for ./img/wiki_up/tiki1/... intiki-admin_security.php?check_files | 6 | Bug: Usability | 2.x | All / Undefined Security | 2006-09 | |
| 1/2 | binddb and bindpw not used when binding to LDAP | 5 | Bug: Error Patch | 1.9.x | External Authentication (LDAP, AD, PAM, CAS, etc) Security User Administration (Registration, Login & Banning) | 2007-10 | |
| 2/2 | Secdb for all files (not just php) | 5 | Feature request | 1.9.x 2.x | Administration Installer (profiles, upgrades and server-related issues) Security | 2007-11 | |
| - | Automatic SVN commit of secdb and syncdb | 5 | Community projects | 2.x | Installer (profiles, upgrades and server-related issues) Security | 2008-04 | |
| - | Logout fails to work when web authorization is selected | 5 | Bug: Usability | 3.x | Security | 2009-04 | |
| - | Enhancement: Use .htpasswd / .htgroup for user access & control | 5 | Feature request | 3.x | Security User Administration (Registration, Login & Banning) | 2009-04 | |
| 1/1 | Image attachements are not saved unique | 5 | Bug: Error Bug: Usability | 1.8.x 1.9.x | Security Wiki (history, page rename, etc) | 2006-04 | |
| - | Security bug which bypasses directory site validation. | 5 | Bug: Error | 1.9.x | Directory (of hyperlinks) Security | 2006-07 | |
| 2/2 | false positive at tikiwiki security error report | 4 | Bug: Usability | 2.x Dogfood on a *.tikiwiki.org site | Security | 2009-02 | |
| 1/4 | mail-in provides no security | 4 | Bug: Error | 1.9.x | Article Mail-in Security Wiki (history, page rename, etc) | 2006-05 | |
| 1/1 | Trackers: ratings fake vote by URL | 3 | Bug: Error | 1.9.x Dogfood on a *.tikiwiki.org site | Rating Security Trackers | 2007-12 | |
| - | Trackback pings should not use fopen to open urls. | 3 | Bug: Error | 1.9.x 2.x | Blog Security XML RPC | 2005-05 | |
| 1/1 | Category plugin lists objects even without perms | 3 | Bug: Security | 1.9.x 2.x | Category Security Wiki Plugin (extends basic syntax) | 2008-01 | |
| - | wiki-edit: footnotes allows html | 3 | Bug: Error | 1.9.x | Security Wiki (history, page rename, etc) | 2006-08 | |
| - | dynamic contents in userdefined modules crashes tiki | 3 | 1.9.x | Dynamic Content Modules Security Wiki Syntax (text area, parser, external wiki, etc) | 2006-08 | ||
| 2/2 | Path disclosure bug in trackers | 2 | Bug: Error | 1.9.x | Security Trackers | 2007-06 | |
| 1/1 | Easy way to deal with SSL when using external images or scripts | 1 low | Feature request | 2.x | Security Stats | 2008-02 | |
| - | Security DB and mods don't work together | 1 low | Bug: Usability Feature request | 2.x | Mods Security | 2008-02 | |
| 2/2 | File gallery: Virus checker | 1 low | Feature request | 3.x | File Gallery Security | 2008-04 | |
| - | Login at workflow.tw.o and info.tw.o fails with XMLRPC Error: 5 | Bug: Error | Dogfood on a *.tikiwiki.org site | Security XML RPC | 2008-12 | ||
| 2/2 | Plugin html should have security, and pass code exactly as is | Feature request | 3.x | Security Wiki Plugin (extends basic syntax) | 2009-03 |
Pending
| Rating | Subject | Priority | Report type | Version | Feature | Created | |
|---|---|---|---|---|---|---|---|
| 2/4 | Optional disabling on javascript stripping protection | 6 | Feature request | 3.x Dogfood on a *.tikiwiki.org site | All / Undefined Permission Security Wiki Plugin (extends basic syntax) Wiki Syntax (text area, parser, external wiki, etc) | 2006-07 | |
| - | Instantaneous visual feedback of password strength | 3 | Feature request | 2.x | Security User Administration (Registration, Login & Banning) | 2008-06 | |
| - | Built it TPL editor removes Javascript from the Templates | 3 | Bug: Usability Feature request | 2.x | Security Theme: Look & feel, Styles, CSS, Theme Control Center | 2005-04 | |
| 1/1 | Security problem with sophisticated google hack on local.php (how to clean up after an intrusion) | 2 | Installer (profiles, upgrades and server-related issues) Security | 2007-11 |
Closed (solved)
| Rating | Subject | Priority | Report type | Version | Feature | Created | |
|---|---|---|---|---|---|---|---|
| 2/2 | XSS vulnerability issue B96 | 9 high | Bug: Error | 1.9.x | Security | 2008-01 | |
| 1/2 | Multimedia Flash unusable due to XSS protection | 9 high | Bug: Error Bug: Regression Bug: Usability | 2.x | Multimedia Security Wiki Syntax (text area, parser, external wiki, etc) | 2008-10 | |
| 2/4 | site based on 2.2 + tikipedia attacked at tiki-browse_image.php from galleries | 9 high | Bug: Usability | 2.x Dogfood on a *.tikiwiki.org site | Image Gallery Security | 2009-02 | |
| 2/2 | Plugins admin interface to activate/deactivate plugins | 9 high | Feature request | 3.x | Administration Security Wiki Plugin (extends basic syntax) WYSIWYCA (What You See is What You Can Access) | 2006-02 | |
| - | tikiwiki version 1.9.5 (CVS) -Sirius- mysql password disclosure & xss | 9 high | Bug: Error | 1.9.x 2.x | Security | 2006-11 | |
| - | Vulnerability in registrating | 9 high | 1.9.x | Security User Administration (Registration, Login & Banning) | 2007-01 | ||
| - | tiki_p_search makes users "admin" | 8 | Bug: Consistency Bug: Error | 2.x | Administration Search Security User Administration (Registration, Login & Banning) | 2008-03 | |
| - | Security:Active XSS in URI allows remote exploitation of user browser | 8 | Bug: Error | Security | 2009-03 | ||
| - | My site totally dead: Warning: ini_set() has been disabled for security reasons | 7 | Bug: Error | 1.9.x | Security | 2007-06 | |
| 2/3 | Forum security issue: Ref: H56 | 7 | Bug: Error | 1.9.x | Forum Security | 2007-07 | |
| - | TikiWiki 2.0: SearchBox Not Displaying for Anonymous Users | 7 | Bug: Usability Support request | 2.x | Search Security | 2008-09 | |
| 1/2 | Wiki cache & plugins: WYSIWYCA problem when admin visits the page (and creates the cache) | 6 | Bug: Error | 1.9.x | Cache Database MySQL Security Wiki (history, page rename, etc) Wiki Plugin (extends basic syntax) | 2007-06 | |
| 2/6 | Wiki cache & plugins: WYSIWYCA problem when admin visits the page (and creates the cache) | 6 | Bug: Error | 2.x 3.x | Article Cache Security Trackers Wiki (history, page rename, etc) Wiki Plugin (extends basic syntax) | 2007-08 | |
| 2/2 | topic permissions not working in tiki-list_articles.php | 6 | Bug: Error Patch Support request | 2.x | Article Permission Security | 2008-11 | |
| - | image gallery: sort_mode=filesize causes mysql error and path disclosure | 5 | Bug: Error | 1.9.x 2.x | Image Gallery Security | 2007-09 | |
| 2/2 | Secdb automatic check with cron job | 5 | Feature request | 1.9.x 2.x | Administration Installer (profiles, upgrades and server-related issues) Security TRIM | 2007-09 | |
| 1/4 | Authenticated RSS | 5 | Feature request | 2.x 3.x | Blog RSS Security | 2008-01 | |
| 2/4 | Better protection against accidental site breakage with improper use of code in modules + template | 4 | Bug: Error Bug: Usability Feature request | 1.9.x | Administration Installer (profiles, upgrades and server-related issues) Modules Security Site Identity Templates (Smarty) | 2007-04 | |
| - | Change Crypt passwords method | 4 | Feature request | 2.x 3.x | Security User Administration (Registration, Login & Banning) | 2008-07 | |
| 2/7 | Restrict possible characters in usernames | 3 | Bug: Error Bug: Usability Feature request | 2.x | Security User Administration (Registration, Login & Banning) | 2007-07 | |
| - | CVE-2006-6457 tikiwiki vulnerable | Bug: Error Support request | 1.9.x | All / Undefined Security | 2007-01 | ||
| - | TikiWiki 2.0: Odd Tags get Inserted into HTML Code | Bug: Consistency Bug: Error Bug: Usability | 2.x | Security Wiki Syntax (text area, parser, external wiki, etc) | 2008-08 | ||
| - | Incorrect permission verification in tiki-upload_file.php | Bug: Security | 3.x | File Gallery Permission Security | 2009-06 | ||
| - | No access permission on articles----articles accessible by articleID for any group | Feature request | 1.9.x | Article Security | 2007-01 |
Contributors to this page: marclaporte
.
Page last modified on Wednesday 04 June, 2008 20:00:28 UTC by marclaporte
.
Sidebar
Sidebar
To register
To have an account at this site, please register at Tikiwiki.org
, and then use that user name and password to log in here.
This site gets user information from Tikiwiki.org with the InterTiki feature.
This site gets user information from Tikiwiki.org with the InterTiki feature.
Last Comments