>> DokuWiki Spell Checker Link Handling Remote Code Execution Vulnerability
Title : DokuWiki Spell Checker Link Handling Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-2142 CVE ID : CVE-2006-2878
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-05
Technical Description
A vulnerability has been identified in DokuWiki, which may be exploited by attackers to compromise a vulnerable web server. This flaw is due to an input validation error in the spell checker that does not properly filter embedded links before being passed to a "preg_replace()" call, which may be exploited by remote attackers to execute arbitrary PHP commands with the privileges of the web server.