CVE-2006-4674 - CVE House
Back to Database
Status published High CVE-2006-4674

Direct static code injection vulnerability in doku.php in DokuWiki before...

Vulnerability Description

Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4674

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

andreas gohr

View all reports →

Affected Software

dokuwiki
Vulnerable Versions:
0, release_2004-07-04, release_2004-07-07, release_2004-07-12, release_2004-07-21, release_2004-07-25, release_2004-08-08, release_2004-08-15a, release_2004-08-22, release_2004-09-12, release_2004-09-25, release_2004-09-30, release_2004-10-19, release_2004-11-01, release_2004-11-02, release_2004-11-10, release_2005-01-14, release_2005-01-15, release_2005-01-16a, release_2005-02-06, release_2005-02-18, release_2005-05-07, release_2005-07-01, release_2005-07-13, release_2005-09-19, release_2005-09-22, release_2006-03-05

Timeline

Official Publish: September 11th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.