MEDIUM
dokuwiki: multiple vulnerabilities in ACL manager
Published Feb 15, 2010
5.0
MEDIUMCVSS 2.0
EPSS 10.81%
Description
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.
Affected products
No data.
OR
- ≤ release_2009-02-14
- 2004-07-04
- 2004-07-07
- 2004-07-12
- 2004-07-21
- 2004-07-25
- 2004-08-08
- 2004-08-15a
- 2004-08-22
- 2004-09-12
- 2004-09-25
- 2004-09-30
- 2004-11-01
- 2004-11-02
- 2004-11-10
- 2005-01-14
- 2005-01-15
- 2005-01-16a
- 2005-02-06
- 2005-02-18
- 2005-05-07
- 2005-07-01
- 2005-07-13
- 2005-09-19
- 2005-09-22
- 2006-03-05
- 2006-03-09
- 2006-03-09e
- 2006-06-04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://bugs.splitbrain.org/index.php?do=details&task_id=1847 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034729.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034831.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/38183 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-201301-07.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2010/dsa-1976 vendor-advisoryx_refsource_DEBIAN
- http://www.exploit-db.com/exploits/11141 exploitx_refsource_EXPLOIT-DB
- http://www.securityfocus.com/bid/37821 vdb-entryx_refsource_BID
- http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2010/0150 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0287 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=556494 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55660 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0287
- https://www.cve.org/CVERecord?id=CVE-2010-0287
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 15, 2010
Updated Aug 7, 2024
Reserved Jan 12, 2010
Link CVE-2010-0287
CISA Vulnrichment
Updated n/a