5
CVSSv2

CVE-2010-0287

Published: 15/02/2010 Updated: 23/09/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki prior to 2009-12-25b allows remote malicious users to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dokuwiki dokuwiki 2006-03-09

dokuwiki dokuwiki 2006-03-05

dokuwiki dokuwiki 2006-06-04

dokuwiki dokuwiki 2006-03-09e

dokuwiki dokuwiki 2005-05-07

dokuwiki dokuwiki 2005-02-18

dokuwiki dokuwiki 2004-11-01

dokuwiki dokuwiki 2004-09-30

dokuwiki dokuwiki 2004-09-25

dokuwiki dokuwiki 2004-07-12

dokuwiki dokuwiki 2004-07-07

dokuwiki dokuwiki

dokuwiki dokuwiki 2005-07-13

dokuwiki dokuwiki 2005-07-01

dokuwiki dokuwiki 2004-11-10

dokuwiki dokuwiki 2004-11-02

dokuwiki dokuwiki 2004-07-25

dokuwiki dokuwiki 2004-07-21

dokuwiki dokuwiki 2005-02-06

dokuwiki dokuwiki 2005-01-16a

dokuwiki dokuwiki 2004-09-12

dokuwiki dokuwiki 2004-08-22

dokuwiki dokuwiki 2004-07-04

dokuwiki dokuwiki 2005-09-22

dokuwiki dokuwiki 2005-09-19

dokuwiki dokuwiki 2005-01-15

dokuwiki dokuwiki 2005-01-14

dokuwiki dokuwiki 2004-08-15a

dokuwiki dokuwiki 2004-08-08

Vendor Advisories

Debian Bug report logs - #565406 ACL can be edited Package: dokuwiki; Maintainer for dokuwiki is Tanguy Ortolo <tanguy+debian@ortoloeu>; Source for dokuwiki is src:dokuwiki (PTS, buildd, popcon) Reported by: "Adrian Lang" <debian@adrianlangde> Date: Fri, 15 Jan 2010 14:18:02 UTC Severity: serious Tags: fixed-upstr ...

Exploits

Reported: 13-01-2010 Patched: 13-01-2010 Released: 14-01-2010 Vulnerable version : wwwsplitbrainorg/_media/projects/dokuwiki/dokuwiki-2009-12-25tgz Patched version: wwwsplitbrainorg/_media/projects/dokuwiki/dokuwiki-2009-12-25btgz Author: white_sheep Contact: white_sheep@ihteamnet ...