Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: GLSA-200606-16 High: DokuWiki PHP Code Injection Threat

gentoo
Calendar Grey June 14, 2006
Scroller Gentoo
A critical security announcement concerning a vulnerability in DokuWiki that permits unauthorized PHP code execution.
A flaw in DokuWiki's spell checker allows for the execution of arbitrary PHP commands, even without proper authentication.

Summary

Gentoo Linux Security Advisory GLSA 200606-16 https://security.gentoo.org/ Severity: High Title: DokuWiki: PHP code injection Date: June 14, 2006 Bugs: #135623 ID: 200606-16

Synopsis ======= A flaw in DokuWiki's spell checker allows for the execution of arbitrary PHP commands, even without proper authentication.
Background ========= DokuWiki is a simple to use wiki targeted at developer teams, workgroups and small companies.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/dokuwiki < 20060309-r1 >= 20060309-r1
========== Stefan Esser discovered that the DokuWiki spell checker fails to properly sanitize PHP's "complex curly syntax".
Impact ===== A unauthentic...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround