|
|
| |
|
| |
dokuwiki: cross-site scripting/request forgery
| Package(s): | dokuwiki |
CVE #(s): | CVE-2012-2129
CVE-2012-2128
|
| Created: | May 29, 2012 |
Updated: | August 13, 2012 |
| Description: |
From the Red Hat bugzilla:
A cross-site scripting (XSS) and cross-site request forgery (CSRF) flaws were found in the way DokuWiki, a standards compliant, simple to use Wiki, performed sanitization of the 'target' parameter when preprocessing edit form data. A remote attacker could provide a specially-crafted URL, which once visited by a valid DokuWiki user would lead to arbitrary HTML or web script execution in the context of logged in DokuWiki user. |
| Alerts: |
|
( Log in to post comments)
|
|
|