>> DokuWiki "w" and "h" Variables Code Injection and Denial of Service Vulnerabilities
Title : DokuWiki "w" and "h" Variables Code Injection and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3851 CVE ID : CVE-2006-5098 - CVE-2006-5099
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-30
Technical Description
Multiple vulnerabilities have been identified in DokuWiki, which could be exploited by attackers to execute arbitrary commands or cause a denial of service. These flaws are due to input validation errors in the "lib/exec/fetch.php" script that does not validate the "w" and "h" parameters, which could be exploited by remote attackers to inject and execute arbitrary shell commands, or exhaust all available resources, creating a denial of service condition.