The ajax_mediadiff function in DokuWiki prior to 2014-05-05a allows remote malicious users to access arbitrary images via a crafted namespace in the ns parameter.
Two vulnerabilities have been discovered in dokuwiki Access control in
the media manager was insufficiently restricted and authentication could
be bypassed when using Active Directory for LDAP authentication
For the stable distribution (wheezy), these problems have been fixed in
version 0020120125b-2+deb7u1
For the unstable distribution (sid), ...