LWN.net Logo

dokuwiki: cross-site scripting/request forgery

Package(s):dokuwiki CVE #(s):CVE-2012-2129 CVE-2012-2128
Created:May 29, 2012 Updated:August 13, 2012
Description: From the Red Hat bugzilla:

A cross-site scripting (XSS) and cross-site request forgery (CSRF) flaws were found in the way DokuWiki, a standards compliant, simple to use Wiki, performed sanitization of the 'target' parameter when preprocessing edit form data. A remote attacker could provide a specially-crafted URL, which once visited by a valid DokuWiki user would lead to arbitrary HTML or web script execution in the context of logged in DokuWiki user.

Alerts:
Fedora FEDORA-2012-6628 2012-05-27
Fedora FEDORA-2012-6630 2012-06-12
Mageia MGASA-2012-0207 2012-08-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds