CVE-2012-2128
published 2012-08-27CVE-2012-2128: Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.24%
65.8th percentile
Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF token."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andreas_gohr | dokuwiki | — | — |
| debian | dokuwiki | < dokuwiki 0.0.20120125a-1 (bookworm) | dokuwiki 0.0.20120125a-1 (bookworm) |
| dokuwiki | dokuwiki | >= 0 < 0.0.20120125a-1 | 0.0.20120125a-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20120125a-1 | 0.0.20120125a-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20120125a-1 | 0.0.20120125a-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20120125a-1 | 0.0.20120125a-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20131208-1 | 0.0.20131208-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8246-cj8p-3gjh: ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2012-2128 [MEDIUM] CWE-352 GHSA-8246-cj8p-3gjh: ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF token."
OSV
CVE-2012-2128: ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku
osv·2012-08-27·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128: ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF token."
OSV
CVE-2012-2128: Cross-site request forgery (CSRF) vulnerability in doku
osv·2012-08-27·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128: Cross-site request forgery (CSRF) vulnerability in doku
Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF token."
Debian
CVE-2012-2128: dokuwiki - Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-...
vendor_debian·2012·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128: dokuwiki - Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-...
Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF token."
Scope: local
bookworm: resolved (fixed in 0.0.20120125a-1)
bullseye: resolved (fixed in 0.0.20120125a-1)
forky: resolved (fixed in 0.0.20120125a-1)
sid: resolved (fixed in 0.0.20120125a-1)
trixie: resolved (fixed in 0.0.20120125a-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [fedora-all]
bugzilla·2012-04-22·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [fedora-all]
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission l
Bugzilla
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data
bugzilla·2012-04-22·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data
A cross-site scripting (XSS) and cross-site request forgery (CSRF) flaws were found in the way DokuWiki, a standards compliant, simple to use Wiki, performed sanitization of the 'target' parameter when preprocessing edit form data. A remote attacker could provide a specially-crafted URL, which once visited by a valid DokuWiki user would lead to arbitrary HTML or web script execution in the context of logged in DokuWiki user.
References:
[1] https://secunia.com/advisories/48848/
[2] http://ircrash.com/uploads/dokuwiki.txt
[3] https://bugs.gentoo.org/show_bug.cgi?id=412891
Discovered by : Khashayar Fereidani
Proof of Concept URL: http://sitename/doku.php?do=edit&
Bugzilla
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [epel-all]
bugzilla·2012-04-22·CVSS 6.8
CVE-2012-2128 [MEDIUM] CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [epel-all]
CVE-2012-2128 CVE-2012-2129 dokuwiki: XSS and CSRF due improper escaping of 'target' parameter in preprocessing edit form data [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission lin
http://bugs.dokuwiki.org/index.php?do=details&task_id=2488http://ircrash.com/uploads/dokuwiki.txthttp://seclists.org/bugtraq/2012/Apr/121http://secunia.com/advisories/48848http://www.openwall.com/lists/oss-security/2012/04/22/4http://www.openwall.com/lists/oss-security/2012/04/23/1http://www.securityfocus.com/bid/53041https://bugzilla.redhat.com/show_bug.cgi?id=815122https://exchange.xforce.ibmcloud.com/vulnerabilities/74907http://bugs.dokuwiki.org/index.php?do=details&task_id=2488http://ircrash.com/uploads/dokuwiki.txthttp://seclists.org/bugtraq/2012/Apr/121http://secunia.com/advisories/48848http://www.openwall.com/lists/oss-security/2012/04/22/4http://www.openwall.com/lists/oss-security/2012/04/23/1http://www.securityfocus.com/bid/53041https://bugzilla.redhat.com/show_bug.cgi?id=815122https://exchange.xforce.ibmcloud.com/vulnerabilities/74907
2012-08-27
Published