dokuwiki: cross-site scripting vulnerability
| Package(s): | dokuwiki | CVE #(s): | CVE-2006-6965 | ||||
| Created: | April 12, 2007 | Updated: | April 18, 2007 | ||||
| Description: | DokuWiki has a cross-site scripting vulnerability that is caused by insufficient user input sanitization of the GET variable 'media' in the fetch.php file. If a user can be tricked into clicking on a specially crafted link, CRLF characters can be injected into the variable allowing arbitrary scripts to be executed with the user's permissions. | ||||||
| Alerts: |
| ||||||
