CVE-2014-8763 — Improper Authentication in Dokuwiki
Severity
5.0MEDIUMNVD
EPSS
1.1%
top 22.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 22
Latest updateMay 17
Description
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
3GHSA▶
GHSA-w8gh-9jqp-v528: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star↗2022-05-17
OSV▶
CVE-2014-8763: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star↗2014-10-22
CVEList▶
CVE-2014-8763: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star↗2014-10-22
📋Vendor Advisories
1Debian▶
CVE-2014-8763: dokuwiki - DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication...↗2014
💬Community
1Bugzilla
▶