Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Gentoo: GLSA-200606-16 High: DokuWiki PHP Code Injection Threat

gentoo
Calendar Grey June 14, 2006
Dist Gentoo Esm H88
A critical security announcement concerning a vulnerability in DokuWiki that permits unauthorized PHP code execution.
A flaw in DokuWiki's spell checker allows for the execution of arbitrary PHP commands, even without proper authentication.

Summary

Gentoo Linux Security Advisory GLSA 200606-16 https://security.gentoo.org/ Severity: High Title: DokuWiki: PHP code injection Date: June 14, 2006 Bugs: #135623 ID: 200606-16

Synopsis ======= A flaw in DokuWiki's spell checker allows for the execution of arbitrary PHP commands, even without proper authentication.
Background ========= DokuWiki is a simple to use wiki targeted at developer teams, workgroups and small companies.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/dokuwiki < 20060309-r1 >= 20060309-r1
========== Stefan Esser discovered that the DokuWiki spell checker fails to properly sanitize PHP's "complex curly syntax".
Impact ===== A unauthentic...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4179841_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here