module

TikiWiki Information Disclosure

Disclosed
2006-11-01
Created
2018-05-30

Description

A vulnerability has been reported in Tikiwiki, which can be exploited by
an anonymous user to dump the MySQL user & passwd just by creating a mysql
error with the "sort_mode" var.

The vulnerability was reported in Tikiwiki version 1.9.5.

Author

Matteo Cantoni goony@nothink.org

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/tikiwiki/tikidblib
msf auxiliary(tikidblib) > show actions
...actions...
msf auxiliary(tikidblib) > set ACTION < action-name >
msf auxiliary(tikidblib) > show options
...show and set options...
msf auxiliary(tikidblib) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.