Several vulnerabilities have been discovered in dokuwiki, a standards compliant
simple to use wiki.
The Common Vulnerabilities and Exposures project identifies the
following problems:
CVE-2010-0287
It was discovered that an internal variable is not properly sanitized before
being used to list directories. This can be exploited to list contents of
arbitrary directories.
CVE-2010-0288
It was discovered that the ACL Manager plugin doesn't properly check the
administrator permissions. This allow an attacker to introduce arbitrary ACL
rules and thus gaining access to a closed Wiki.
CVE-2010-0289
It was discovered that the ACL Manager plugin doesn't have protections against
cross-site request forgeries (CSRF). This can be exploited to change the
access control rules by tricking a logged in administrator into visiting
a malicious web site.
The oldstable distribution (etch) is not affected by these problems.
For the stable distribution (lenny), these problems have been fixed in
version 0.0.20080505-4+lenny1.
F...
Get the latest Linux and open source security news straight to your inbox.