Vulnerabilities
Vulnerable Software
DokuWiki before 2023-04-04a allows XSS via RSS titles.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-06-05
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-09-05
HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-05-12
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.
CVSS Score
5.0
EPSS Score
0.085
Published
2010-02-15
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.
CVSS Score
7.5
EPSS Score
0.156
Published
2010-02-15
Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.
CVSS Score
6.8
EPSS Score
0.004
Published
2010-02-15


Contact Us

Shodan ® - All rights reserved