7.5
CVSSv2

CVE-2006-5099

Published: 29/09/2006 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

lib/exec/fetch.php in DokuWiki prior to 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote malicious users to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert.

Vulnerable Product Search on Vulmon Subscribe to Product

andreas gohr dokuwiki release_2006-03-05

andreas gohr dokuwiki release_2006-03-09

andreas gohr dokuwiki release_2006-03-09e

Vendor Advisories

Debian Bug report logs - #391291 CVE-2006-509[89]: DokuWiki 2006-03-09e fixes security issues Package: dokuwiki; Maintainer for dokuwiki is Tanguy Ortolo <tanguy+debian@ortoloeu>; Source for dokuwiki is src:dokuwiki (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Thu, 5 Oct 2006 21:04:05 UT ...