PT-2016-7448 · Dokuwiki+1 · Dokuwiki+1

Ambulong

+1

·

Publicado

2016-10-31

·

Atualizado

2016-11-28

·

CVE-2016-7965

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions DokuWiki versions 2016-06-26a and older
Description The issue allows a remote unauthenticated attacker to change the hostname in the password-reset URL via the HTTP Host header, potentially leading to phishing attacks. This can be triggered if the Host header is not part of the web server routing process, such as when multiple domains are served by the same web server.
Recommendations For DokuWiki versions 2016-06-26a and older, consider updating to a version that uses the baseurl setting instead of $ SERVER['HTTP HOST'] for the password-reset URL. As a temporary workaround, ensure that the Host header is part of the web server routing process to prevent exploitation. Restrict access to the password-reset functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7965

Produtos afetados

Debian
Dokuwiki