Dokuwiki

Dokuwiki

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.66%
  • Veröffentlicht 20.11.2012 00:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 23.09.2011 23:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files.

  • EPSS 0.86%
  • Veröffentlicht 14.07.2011 23:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.

  • EPSS 0.4%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control r...

  • EPSS 15.61%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the ...

  • EPSS 8.49%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.

  • EPSS 39.04%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remo...