|
|
>> DokuWiki Access Control Lists Bypass and Restricted Content Disclosure Issue
|
Title : DokuWiki Access Control Lists Bypass and Restricted Content Disclosure Issue VUPEN ID : VUPEN/ADV-2006-2172 CVE ID : CVE-2006-2945
Rated as : Low Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-07
|
A vulnerability has been identified in DokuWiki, which could be exploited by malicious users to bypass security restrictions. This flaw is due to an error in the "inc/action.php" script that does not properly check user privileges before granting access to restricted pages, which could be exploited by authenticated attackers to bypass Access Control Lists and gain access to restricted areas and content.
Affected Products
DokuWiki
Solution
Upgrade to the latest version :
http://www.splitbrain.org/projects/dokuwiki
References
http://www.vupen.com/english/advisories/2006/2172 http://bugs.splitbrain.org/?do=details&id=825
Credits
Vulnerability reported by Andreas Akre Solberg
ChangeLog
2006-06-07 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|