Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2172
HistoryMar 30, 2015 - 12:00 a.m.

CVE-2015-2172

2015-03-3000:00:00
ubuntu.com
ubuntu.com
15

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.011

Percentile

84.1%

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check
permissions for the ACL plugins, which allows remote authenticated users to
gain privileges and add or delete ACL rules via a request to the XMLRPC
API.

Bugs

Notes

Author Note
tyhicks Vulnerability is in XMLRPC API that is marked experimental and off by default

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.011

Percentile

84.1%