In association with heise online

27 May 2009, 12:08

Security Update for DokuWiki

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The 2009-02-14b update for the DokuWiki Wiki System eliminates a vulnerability which could allow an attacker to compromise a vulnerable system. The config_cascade Parameters in inc/init.php were un-verified, allowing a PHP script to be inserted and run.

The published exploit shows how local files can be exploited, but should also work for external sites. For an attack to be successful, the PHP register_globals option must be enabled.



Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit