Vulnerability Description
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tikiwiki Cms\/Groupware | 8.3 |
Related Weaknesses (CWE)
References
- http://osvdb.org/79409
- http://secunia.com/advisories/48102Vendor Advisory
- http://st2tea.blogspot.com/2012/02/tiki-wiki-cms-groupware-frame-injection.htmlExploit
- http://www.securityfocus.com/bid/52079Exploit
- http://www.securitytracker.com/id?1026708Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73403
- http://osvdb.org/79409
- http://secunia.com/advisories/48102Vendor Advisory
- http://st2tea.blogspot.com/2012/02/tiki-wiki-cms-groupware-frame-injection.htmlExploit
- http://www.securityfocus.com/bid/52079Exploit
- http://www.securitytracker.com/id?1026708Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73403
FAQ
What is CVE-2012-5321?
CVE-2012-5321 is a vulnerability with a CVSS score of 5.8 (MEDIUM). tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."
How severe is CVE-2012-5321?
CVE-2012-5321 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5321?
Check the references section above for vendor advisories and patch information. Affected products include: Tiki Tikiwiki Cms\/Groupware.