LWN.net Logo

dokuwiki: cross-site scripting vulnerability

Package(s):dokuwiki CVE #(s):CVE-2006-6965
Created:April 12, 2007 Updated:April 18, 2007
Description: DokuWiki has a cross-site scripting vulnerability that is caused by insufficient user input sanitization of the GET variable 'media' in the fetch.php file. If a user can be tricked into clicking on a specially crafted link, CRLF characters can be injected into the variable allowing arbitrary scripts to be executed with the user's permissions.
Alerts:
Gentoo 200704-08 2007-04-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds