TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
- http://www.exploit-db.com/exploits/19573
- http://www.exploit-db.com/exploits/19630
No PoCs found on GitHub currently.