The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does...
Vulnerability Description
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-18123
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/splitbrain/dokuwiki/pull/2019
- https://vulnhive.com/2018/000004
- https://lists.debian.org/debian-lts-announce/2018/02/msg00004.html
- https://lists.debian.org/debian-lts-announce/2018/07/msg00004.html
- https://github.com/splitbrain/dokuwiki/commit/238b8e878ad48f370903465192b57c2072f65d86
- https://hackerone.com/reports/238316
- https://github.com/splitbrain/dokuwiki/issues/2029
More from dokuwiki
View All →Affected Vendor
dokuwiki
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.