In association with heise online

27 May 2009, 13:08

Security Update for DokuWiki

The 2009-02-14b update for the DokuWiki Wiki System eliminates a vulnerability which could allow an attacker to compromise a vulnerable system. The config_cascade Parameters in inc/init.php were un-verified, allowing a PHP script to be inserted and run.

The published exploit shows how local files can be exploited, but should also work for external sites. For an attack to be successful, the PHP register_globals option must be enabled.

(dab)

(crve)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit