5
CVSSv2

CVE-2014-8764

Published: 22/10/2014 Updated: 15/07/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

DokuWiki 2014-05-05a and previous versions, when using Active Directory for LDAP authentication, allows remote malicious users to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.

Vulnerable Product Search on Vulmon Subscribe to Product

mageia project mageia 4.0

mageia project mageia 3.0

dokuwiki dokuwiki

Vendor Advisories

Debian Bug report logs - #766545 CVE-2014-8763 CVE-2014-8764 Package: dokuwiki; Maintainer for dokuwiki is Tanguy Ortolo <tanguy+debian@ortoloeu>; Source for dokuwiki is src:dokuwiki (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 23 Oct 2014 21:12:19 UTC Severity: important Tags: ...
Debian Bug report logs - #773429 dokuwiki: CVE-2014-9253 Package: dokuwiki; Maintainer for dokuwiki is Tanguy Ortolo <tanguy+debian@ortoloeu>; Source for dokuwiki is src:dokuwiki (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 18 Dec 2014 10:09:02 UTC Severity: important Tags: secu ...
Two vulnerabilities have been discovered in dokuwiki Access control in the media manager was insufficiently restricted and authentication could be bypassed when using Active Directory for LDAP authentication For the stable distribution (wheezy), these problems have been fixed in version 0020120125b-2+deb7u1 For the unstable distribution (sid), ...