CVE-2004-1928

Tiki CMS/Groupware < 1.8.1 - Arbitrary File Upload via Image Upload Feature

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-1928. PoCs published by JeiAr.

AI-analyzed exploit summary The provided text is a brief writeup describing multiple vulnerabilities in an unspecified application, including path disclosure, XSS, SQL injection, and arbitrary file upload. It references a generic example URL but lacks exploit code or technical details.

Description

The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.

Exploits (2)

exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/23948

The provided text is a brief writeup describing multiple vulnerabilities in an unspecified application, including path disclosure, XSS, SQL injection, and arbitrary file upload. It references a generic example URL but lacks exploit code or technical details.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/43809

This is a detailed technical writeup describing multiple vulnerabilities in TikiWiki CMS/Groupware, including path disclosure, XSS, SQL injection, code injection, file enumeration, and arbitrary file upload. It provides specific examples of vulnerable endpoints and attack vectors.

Classification
Writeup 100%
Attack Type
Info Leak | Xss | Sqli | Other
Complexity
Moderate
Reliability
Reliable
Target: TikiWiki CMS/Groupware <= 1.8.1
No auth needed
Prerequisites: Access to vulnerable TikiWiki installation
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10100
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108180073206947&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15849
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11344
Patch, Vendor Advisory x_refsource_confirm
http://tikiwiki.org/tiki-read_article.php?articleId=66

Scores

EPSS 0.0311
EPSS Percentile 86.1%

Details

CWE
CWE-20
Status published
Products (2)
tiki/tikiwiki_cms\/groupware 1.6.1
tiki/tikiwiki_cms\/groupware < 1.8.1
Published Apr 12, 2004
Tracked Since Feb 18, 2026