MidnightBSD

Advisories for yeswiki

CVE-2018-1000641 HIGH

YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
yeswiki yeswiki 2016-03-17-1
yeswiki yeswiki 2013-10-17-1
yeswiki yeswiki 2012-10-22-1
CVE-2018-13045 HIGH

SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
yeswiki cercopitheque *