CVE-2006-5702

Tikiwiki Cms/groupware - Information Disclosure

Title source: rule

Description

Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.

Exploits (2)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/2701
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/tikiwiki/tikidblib.rb

Scores

EPSS 0.5342
EPSS Percentile 98.0%

Details

CWE
CWE-200
Status published
Products (1)
tiki/tikiwiki_cms\/groupware 1.9.5
Published Nov 04, 2006
Tracked Since Feb 18, 2026