Debian Dokuwiki vulnerabilities

40 known vulnerabilities affecting debian/dokuwiki.

Total CVEs
40
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM20LOW18

Vulnerabilities

Page 2 of 2
CVE-2012-2128LOWCVSS 6.8fixed in dokuwiki 0.0.20120125a-1 (bookworm)2012
CVE-2012-2128 [MEDIUM] CVE-2012-2128: dokuwiki - Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-... Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF
debian
CVE-2012-2129LOWCVSS 4.3fixed in dokuwiki 0.0.20120125a-1 (bookworm)2012
CVE-2012-2129 [MEDIUM] CVE-2012-2129: dokuwiki - Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angu... Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action. Scope: local bookworm: resolved (fixed in 0.0.20120125a-1) bullseye: resolved (fixed in 0.0.20120125a-1) forky: resolved (fixed in 0.0.20120125a-1) sid: resolved (fixed in 0.0.20
debian
CVE-2012-0283LOWCVSS 4.3fixed in dokuwiki 0.0.20120125b-1 (bookworm)2012
CVE-2012-0283 [MEDIUM] CVE-2012-0283: dokuwiki - Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in in... Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php. Scope: local bookworm: resolved (fixed in 0.0.20120125b-1) bullseye: resolved (fixed in 0.0.20120125b-1) forky: re
debian
CVE-2011-2510LOWCVSS 4.3fixed in dokuwiki 0.0.20110525a-1 (bookworm)2011
CVE-2011-2510 [MEDIUM] CVE-2011-2510: dokuwiki - Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWik... Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link. Scope: local bookworm: resolved (fixed in 0.0.20110525a-1) bullseye: resolved (fixed in 0.0.20110525a-1) forky: resolved (fixed in 0.0.20110525a-1) sid: resolved (fixed in 0.0.20110
debian
CVE-2010-0288MEDIUMCVSS 7.5ExploitedPoCfixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0288 [HIGH] CVE-2010-0288: dokuwiki - A typo in the administrator permission check in the ACL Manager plugin (plugins/... A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010. Scope: local bookworm: resolved (fixed in 0.0.20090214b-3.1) bullseye: resolved (fixed in 0.0.200
debian
CVE-2010-0287LOWCVSS 5.0PoCfixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0287 [MEDIUM] CVE-2010-0287: dokuwiki - Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.ph... Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter. Scope: local bookworm: resolved (fixed in 0.0.20090214b-3.1) bullseye: resolved (fixed in 0.0.20090214b-3.1) forky: resolved (fixed in 0.0.2009
debian
CVE-2010-0289LOWCVSS 6.8fixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0289 [MEDIUM] CVE-2010-0289: dokuwiki - Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager pl... Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors. Scope: local bookworm: resolved (fixed in 0.0.20090214b-3.
debian
CVE-2009-1960LOWCVSS 9.3PoCfixed in dokuwiki 0.0.20090214b-1 (bookworm)2009
CVE-2009-1960 [CRITICAL] CVE-2009-1960: dokuwiki - inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when regist... inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs. Scope: local bookworm: resolved (fixed in 0.0.2009021
debian
CVE-2008-5186LOWCVSS 7.5fixed in dokuwiki 0.0.20080505-3.1 (bookworm)2008
CVE-2008-5186 [HIGH] CVE-2008-5186: dokuwiki - The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi... The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi.
debian
CVE-2006-2878HIGHCVSS 7.5fixed in dokuwiki 0.0.20060309-4 (bookworm)2006
CVE-2006-2878 [HIGH] CVE-2006-2878: dokuwiki - The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remo... The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier. Scope: local bookworm: resolved (fixed in 0.0.20060309-4) bullseye: resolved (fixed in 0.0.20060
debian
CVE-2006-5099MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.2 (bookworm)2006
CVE-2006-5099 [HIGH] CVE-2006-5099: dokuwiki - lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is confi... lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert. Scope: local bookworm: resolved (fixed in 0.0.20060309-5.2) bullseye: resolved (fixed in 0.0.20060309-5
debian
CVE-2006-4675MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4675 [HIGH] CVE-2006-4675: dokuwiki - Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2... Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.0.20060309-5.1) bullseye: resolved (fixed in 0.0.20060309-5.1) forky: resolved (fixed in 0.0.20060309-5.1) sid: resolved (fixed in
debian
CVE-2006-5098MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20060309-5.2 (bookworm)2006
CVE-2006-5098 [MEDIUM] CVE-2006-5098: dokuwiki - lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cau... lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image. Scope: local bookworm: resolved (fixed in 0.0.20060309-5.2) bullseye: resolved (fixed in 0.0.20060309-5.2) forky: resolved (fixed in 0.0.20060309-5.2) sid: resolved (fixed in 0.0.20060309-5.2)
debian
CVE-2006-1165MEDIUMCVSS 4.3fixed in dokuwiki 0.0.20060309-3 (bookworm)2006
CVE-2006-1165 [MEDIUM] CVE-2006-1165: dokuwiki - Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki ... Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data." Scope: local bookworm: resolved (fixed in 0.0.20060309-3) bullseye: resolved (fixed in 0.0.20060309-3) forky: resolved (fixed in 0.0.20060309-3)
debian
CVE-2006-4674MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4674 [HIGH] CVE-2006-4674: dokuwiki - Direct static code injection vulnerability in doku.php in DokuWiki before 2006-0... Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. Scope: local bookworm: resolved (fixed in 0.0.20060309-5.1) bullseye: resolved (fixed in 0.0.20060309-5.1) forky: resolved (fixed in 0.0.20060309-5.1) sid: reso
debian
CVE-2006-6965LOWCVSS 4.3fixed in dokuwiki 0.0.20061106-1 (bookworm)2006
CVE-2006-6965 [MEDIUM] CVE-2006-6965: dokuwiki - CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and p... CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks. Scope: local bookworm: resolved (fixed in 0.0.20061106-1) bullseye: resolve
debian
CVE-2006-4679LOWCVSS 5.0fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4679 [MEDIUM] CVE-2006-4679: dokuwiki - DokuWiki before 2006-03-09c enables the debug feature by default, which allows r... DokuWiki before 2006-03-09c enables the debug feature by default, which allows remote attackers to obtain sensitive information by calling doku.php with the X-DOKUWIKI-DO HTTP header set to "debug". Scope: local bookworm: resolved (fixed in 0.0.20060309-5.1) bullseye: resolved (fixed in 0.0.20060309-5.1) forky: resolved (fixed in 0.0.20060309-5.1) sid: resolved (fi
debian
CVE-2006-2945LOWCVSS 4.0fixed in dokuwiki 0.0.20060309-4 (bookworm)2006
CVE-2006-2945 [MEDIUM] CVE-2006-2945: dokuwiki - Unspecified vulnerability in the user profile change functionality in DokuWiki, ... Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors. Scope: local bookworm: resolved (fixed in 0.0.20060309-4) bullseye: resolved (fixed in 0.0.20060309-4) forky: resolved (fixed in 0.0.20060309-4) sid: resolved
debian
CVE-2004-2559LOWCVSS 7.52004
CVE-2004-2559 [HIGH] CVE-2004-2559: dokuwiki - DokuWiki before 2004-10-19 allows remote attackers to access administrative func... DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2004-2560LOWCVSS 7.52004
CVE-2004-2560 [HIGH] CVE-2004-2560: dokuwiki - DokuWiki before 2004-10-19, when used on a web server that permits execution bas... DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi". Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian