PT-2014-8717 · Dokuwiki · Dokuwiki

Publicado

2014-10-22

·

Atualizado

2016-04-04

·

CVE-2014-8762

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DokuWiki versions prior to 2014-05-05a
Description The issue allows remote attackers to access arbitrary images through a manipulated namespace in the ns parameter of the ajax mediadiff function.
Recommendations For versions prior to 2014-05-05a, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the ajax mediadiff function until a patch is available. Avoid using the ns parameter in the affected function until the issue is resolved.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8762
DSA-3059-1
MGASA-2014-0438

Produtos afetados

Dokuwiki