vendor:
Portili Personal and Team Wiki
by:
Abysssec Inc
N/A
CVSS
N/A
Admin Password Disclosure Exploit
CWE
Product Name: Portili Personal and Team Wiki
Affected Version From: Portili Personal and Team Wik <= 1.14
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
Unknown
Portili Personal and Team Wiki Multiple Remote Vulnerabilities
There is an interesting vulnerability in the code of ajaxfilemanager/ajax_save_name.php. The vulnerability allows for the disclosure of the admin password.
Mitigation:
The vendor has fixed all the vulnerabilities and will release the fixes in the next version of the wiki.