|
|
| |
|
| |
dokuwiki: cross-site scripting vulnerability
| Package(s): | dokuwiki |
CVE #(s): | CVE-2006-6965
|
| Created: | April 12, 2007 |
Updated: | April 18, 2007 |
| Description: |
DokuWiki has a cross-site scripting vulnerability that is caused by
insufficient user input sanitization of the GET variable 'media' in
the fetch.php file. If a user can be tricked into clicking on a
specially crafted link, CRLF characters can be injected into the variable
allowing arbitrary scripts to be executed with the user's permissions. |
| Alerts: |
|
( Log in to post comments)
|
|
|