Andreas Gohr
Andreas Gohr Dokuwiki: vulnerabilidades y CVE
Andreas Gohr Dokuwiki tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2012-2129 | Media (4.3) | 2.6% | — | 27 ago 2012 | Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action. |
| CVE-2012-2128 | Media (6.8) | 1.2% | — | 27 ago 2012 | Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has… |
| CVE-2012-0283 | Media (4.3) | 1.4% | — | 13 jul 2012 | Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a… |
| CVE-2006-6965 | Media (4.3) | 1.4% | — | 29 ene 2007 | CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in… |
| CVE-2006-5099 | Alta (7.5) | 2.2% | — | 29 sept 2006 | lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters,… |
| CVE-2006-5098 | Media (5) | 1.7% | — | 29 sept 2006 | lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image. |
| CVE-2006-4679 | Media (5) | 1.7% | — | 11 sept 2006 | DokuWiki before 2006-03-09c enables the debug feature by default, which allows remote attackers to obtain sensitive information by calling doku.php with the X-DOKUWIKI-DO HTTP header set to "debug". |
| CVE-2006-4674 | Alta (7.5) | 1.9% | — | 11 sept 2006 | Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. |
| CVE-2006-4675 | Alta (7.5) | 1.9% | — | 11 sept 2006 | Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors. |
| CVE-2006-2945 | Media (4) | 1.1% | — | 12 jun 2006 | Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors. |
| CVE-2006-2878 | Alta (7.5) | 14% | — | 7 jun 2006 | The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is… |
| CVE-2006-1165 | Media (4.3) | 1.2% | — | 12 mar 2006 | Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF… |
| CVE-2004-2559 | Alta (7.5) | 1.6% | — | 31 dic 2004 | DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks. |
| CVE-2004-2560 | Alta (7.5) | 2.8% | — | 31 dic 2004 | DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or… |