DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.
Link | Tags |
---|---|
http://securitytracker.com/id?1011802 | vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17799 | vdb entry |
http://www.osvdb.org/11005 | vdb entry |
http://wiki.splitbrain.org/wiki:old_changes |