Lucene search

K
freebsdFreeBSD4F838B74-50A1-11DE-B01F-001C2514716C
HistoryMay 26, 2009 - 12:00 a.m.

dokuwiki -- Local File Inclusion with register_globals on

2009-05-2600:00:00
vuxml.freebsd.org
28

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.23

Percentile

96.6%

DokuWiki reports:

A security hole was discovered which allows an attacker
to include arbitrary files located on the attacked DokuWiki
installation. The included file is executed in the PHP context.
This can be escalated by introducing malicious code through
uploading file via the media manager or placing PHP code in
editable pages.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchdokuwiki< 20090214_2UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.23

Percentile

96.6%