[Show/Hide Right Column]

Tracker Item: Bugs & Wish list Help

View

View Item

Statusclosed closed
Rating -2-1012(1)Help
Ticket ID 1498
Subject XSS vulnerability issue B96
Submitted by Fortify
Priority 9 high
Category Bug: Error
Tiki Version 1.9.x
Feature Security
Description

We found a cross-site scripting vulnerability. Details have been sent to security.tikiwiki.org

Solution

Fixed in TikiWiki 1.9.10.1

More info: http://secunia.com/advisories/29092/

Technical Area PHP
Resolution status (legacy) Fixed
Lastmod by Marc Laporte
Created Tuesday 22 January, 2008 22:42:14 UTC
LastModif Tuesday 26 February, 2008 14:26:32 UTC
Comments (0)

Comments

Attachments (0)

Attachments

 filenamecreatedfilesize 
No attachments for this item


Search Wishes (subject only)

Keywords

The following is a list of keywords that should serve as hubs for navigation within the Tiki development and should correspond to documentation keywords.

Each feature in Tiki has a wiki page which regroups all the bugs, requests for enhancements, etc. It is somewhat a form of wiki-based project management. You can also express your interest in a feature by adding it to your profile. You can also try out the Dynamic filter.


Show php error messages
 
PHP (5.2.10-2ubuntu6.4) NOTICE (E_NOTICE):
File: tiki-view_tracker_item.php
Line: 411
Type: Undefined variable: group
PHP (5.2.10-2ubuntu6.4) NOTICE (E_NOTICE):
File: lib/smarty_tiki/modifier.username.php
Line: 19
Type: Undefined index: realName