Bug#388122: [pkg-tikiwiki-devel] Bug#388122: CVE-2006-4734: tikiwiki arbitrary SQL execution vulnerability

2006-09-19 Thread Marcus Better
This issue does not seem to affect Tikiwiki 1.9.5. I will apply some security checks from upstream anyway and make a new release. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#388122: CVE-2006-4734: tikiwiki arbitrary SQL execution vulnerability

2006-09-18 Thread Stefan Fritsch
Package: tikiwiki Severity: grave Tags: security Justification: user security hole A security issue has been found in tikiwiki: Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) w