CVE-2012-3354
Summary
| CVE | CVE-2012-3354 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-20 00:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dokuwiki | Dokuwiki | - | All | All | All |
| Operating System | Fedoraproject | Fedora | 16 | All | All | All |
| Operating System | Fedoraproject | Fedora | 17 | All | All | All |
| Operating System | Fedoraproject | Fedora | 18 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 835145 – CVE-2012-3354 dokuwiki: Full path disclosure with PHP error level enabled | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Support / Security / Advisories / / MDVSA-2013:073 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| oss-security - Re: CVE request: Full path disclosure in DokuWiki | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 18 Update: dokuwiki-0-0.14.20121013.fc18 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 17 Update: dokuwiki-0-0.14.20121013.fc17 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [dokuwiki] Fwd: DokuWiki - Full path disclosure - dokuwiki - FreeLists | af854a3a-2127-422b-91ae-364da2661108 | www.freelists.org | |
| oss-security - CVE request: Full path disclosure in DokuWiki | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 16 Update: dokuwiki-0-0.14.20121013.fc16 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.