Dokuwiki

Dokuwiki

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 22.10.2014 14:55:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.

  • EPSS 0.66%
  • Veröffentlicht 20.11.2012 00:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 23.09.2011 23:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files.

  • EPSS 0.86%
  • Veröffentlicht 14.07.2011 23:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.

  • EPSS 0.4%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control r...

  • EPSS 27.18%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the ...

  • EPSS 10.87%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.

  • EPSS 39.04%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remo...