The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/61983 | third party advisory |
http://advisories.mageia.org/MGASA-2014-0438.html | |
https://github.com/splitbrain/dokuwiki/issues/765 | |
http://www.securityfocus.com/bid/70404 | vdb entry |
http://www.openwall.com/lists/oss-security/2014/10/13/3 | mailing list |
http://www.openwall.com/lists/oss-security/2014/10/16/9 | mailing list |
http://www.debian.org/security/2014/dsa-3059 | vendor advisory |