VYPR

DokuWiki

by Splitbrain

Source repositories

CVEs (6)

  • CVE-2009-1960Jun 8, 2009
    risk 0.05cvss epss 0.23

    inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also…

  • CVE-2006-2878Jun 7, 2006
    risk 0.01cvss epss 0.14

    The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.

  • CVE-2022-3123MedSep 5, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

  • CVE-2017-18123HigFeb 3, 2018
    risk 0.00cvss 8.6epss 0.03

    The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.

  • CVE-2015-2172Mar 30, 2015
    risk 0.00cvss epss 0.03

    DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

  • CVE-2014-8762Oct 22, 2014
    risk 0.00cvss epss 0.02

    The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.

VYPR — Vulnerability Intelligence