Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-2172

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.0%
CVSS Severity
CVSS v2 Score 6.5
References
Products affected by CVE-2015-2172
  • Dokuwiki » Dokuwiki » Version: 2014-05-05
    cpe:2.3:a:dokuwiki:dokuwiki:2014-05-05
  • Dokuwiki » Dokuwiki » Version: 2014-05-05a
    cpe:2.3:a:dokuwiki:dokuwiki:2014-05-05a
  • Dokuwiki » Dokuwiki » Version: 2014-05-05b
    cpe:2.3:a:dokuwiki:dokuwiki:2014-05-05b
  • Dokuwiki » Dokuwiki » Version: 2014-05-05c
    cpe:2.3:a:dokuwiki:dokuwiki:2014-05-05c
  • Dokuwiki » Dokuwiki » Version: 2014-09-29
    cpe:2.3:a:dokuwiki:dokuwiki:2014-09-29
  • Dokuwiki » Dokuwiki » Version: 2014-09-29a
    cpe:2.3:a:dokuwiki:dokuwiki:2014-09-29a
  • Dokuwiki » Dokuwiki » Version: 2014-09-29b
    cpe:2.3:a:dokuwiki:dokuwiki:2014-09-29b


Contact Us

Shodan ® - All rights reserved