Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1960

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.307
EPSS Ranking 96.6%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-1960
  • Dokuwiki » Dokuwiki » Version: 2009-02-14
    cpe:2.3:a:dokuwiki:dokuwiki:2009-02-14
  • Dokuwiki » Dokuwiki » Version: rc2009-01-30
    cpe:2.3:a:dokuwiki:dokuwiki:rc2009-01-30
  • Dokuwiki » Dokuwiki » Version: rc2009-02-06
    cpe:2.3:a:dokuwiki:dokuwiki:rc2009-02-06


Contact Us

Shodan ® - All rights reserved