Security
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Web Development Archives Mailing Lists Security

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Web Development Archives Sponsor:
  #1  
Old June 14th, 2006, 02:00 PM
Sune Kloppenborg Jeppesen
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
DokuWiki: PHP code injection

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200606-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: DokuWiki: PHP code injection
Date: June 14, 2006
Bugs: #135623
ID: 200606-16

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis


A flaw in DokuWiki's spell checker allows for the execution of
arbitrary PHP commands, even without proper authentication.

Background


DokuWiki is a simple to use wiki targeted at developer teams,
workgroups and small companies.

Affected packages



Package / Vulnerable / Unaffected

1 www-apps/dokuwiki < 20060309-r1 >= 20060309-r1

Description


Stefan Esser discovered that the DokuWiki spell checker fails to
properly sanitize PHP's "complex curly syntax".

Impact


A unauthenticated remote attacker may execute arbitrary PHP commands -
and thus possibly arbitrary system commands - with the permissions of
the user running the webserver that serves DokuWiki pages.

Workaround


There is no known workaround at this time.

Resolution


All DokuWiki users should upgrade to the latest version:

# emerge
# emerge ">=www-apps/dokuwiki-20060309-r1"

References


[ 1 ] Hardened-PHP advisory

[ 2 ] CVE-2006-2878


Availability


This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:



Concerns?


Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security (AT) gentoo (DOT) org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License


Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.




Full-Disclosure - We believe in it.
Charter:
Hosted and sponsored by Secunia - http://secunia.com/
PGP SIGNATURE
Version: GnuPG v1.4.2.2 (GNU/Linux)


QYZB7fWP33y32keDJMPlZYU=
=aflA
PGP SIGNATURE

Reply With Quote
Reply

Viewing: Web Development Archives Mailing Lists Security > DokuWiki: PHP code injection


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 3 Hosted by Hostway
Stay green...Green IT