DokuWiki Multiple Input Validation Vulnerabilities
BID:19911
Info
DokuWiki Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 19911 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4674 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2006 12:00AM |
| Updated: | Jul 06 2016 01:32PM |
| Credit: | rgod is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
MySource MySource 2.14.6 Gentoo Linux |
| Not Vulnerable: |
MySource MySource 2.14.8 |
Discussion
DokuWiki Multiple Input Validation Vulnerabilities
DokuWiki is prone to multiple input-validation vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts and to run it in the context of the webserver process.
A successful attack may result in unauthorized access.
DokuWiki is prone to multiple input-validation vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts and to run it in the context of the webserver process.
A successful attack may result in unauthorized access.
Exploit / POC
DokuWiki Multiple Input Validation Vulnerabilities
Attackers can exploit this issue via a web client.
Sample exploit code has been provided:
Attackers can exploit this issue via a web client.
Sample exploit code has been provided:
Solution / Fix
DokuWiki Multiple Input Validation Vulnerabilities
Solution:
The vendor has released version 2006-03-09c to address these issues. Please see the references for more information.
Solution:
The vendor has released version 2006-03-09c to address these issues. Please see the references for more information.
References
DokuWiki Multiple Input Validation Vulnerabilities
References:
References: