PT-2007-1245 · Dokuwiki · Dokuwiki
Publicado
2007-01-29
·
Atualizado
2017-07-29
·
CVE-2006-6965
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
DokuWiki versions prior to 2006-03-09e
Description:
A CRLF injection issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the
media parameter. This issue can also be leveraged for XSS attacks.Recommendations:
For versions prior to 2006-03-09e, update to a version that includes the fix for this issue to prevent CRLF injection and potential XSS attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dokuwiki