CVE-2006-6457
Last modified
CVE-2006-6457 is a vulnerability of currently unknown severity. tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tikiwiki Cms\/Groupware | 1.9.2 |
| Tiki | Tikiwiki Cms\/Groupware | 1.9.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6457?
How severe is CVE-2006-6457?
How do I fix CVE-2006-6457?
Are you affected by CVE-2006-6457?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
