CVE-2006-2878 - CVE House
Back to Database
Status published High CVE-2006-2878

The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote...

Vulnerability Description

The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2878

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

andreas gohr

View all reports →

Affected Software

dokuwiki
Vulnerable Versions:
0, release_2004-07-04, release_2004-07-07, release_2004-07-12, release_2004-07-21, release_2004-07-25, release_2004-08-08, release_2004-08-15a, release_2004-08-22, release_2004-09-12, release_2004-09-25, release_2004-09-30, release_2004-10-19, release_2004-11-01, release_2004-11-02, release_2004-11-10, release_2005-01-14, release_2005-01-15, release_2005-01-16a, release_2005-02-06, release_2005-02-18, release_2005-05-07, release_2005-07-01, release_2005-07-13, release_2005-09-19, release_2005-09-22, release_2006-03-05

Timeline

Official Publish: June 7th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.