LWN.net Logo

dokuwiki: arbitrary command execution

Package(s):dokuwiki CVE #(s):CVE-2006-4674 CVE-2006-4675 CVE-2006-4679
Created:September 15, 2006 Updated:September 20, 2006
Description: "rgod" discovered that DokuWiki doesn't sanitize the X-FORWARDED-FOR HTTP header, allowing the injection of arbitrary contents - such as PHP commands - into a file. Additionally, the accessory scripts installed in the "bin" DokuWiki directory are vulnerable to directory traversal attacks, allowing to copy and execute the previously injected code.
Alerts:
Gentoo 200609-10 2006-09-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds