Security Update for DokuWiki
The 2009-02-14b update for the DokuWiki Wiki System eliminates a vulnerability which could allow an attacker to compromise a vulnerable system. The config_cascade Parameters in inc/init.php
were un-verified, allowing a PHP script to be inserted and run.
The published exploit shows how local files can be exploited, but should also work for external sites. For an attack to be successful, the PHP register_globals
option must be enabled.
(dab)
(crve)