Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2172

Опубликовано: 30 мар. 2015
Источник: debian
EPSS Низкий

Описание

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dokuwikifixed0.0.20140929.d-1package
dokuwikifixed0.0.20140505.a+dfsg-4jessiepackage
dokuwikinot-affectedsqueezepackage
dokuwikinot-affectedwheezypackage

Примечания

  • present since release_candidate_2013-10-28

  • https://github.com/splitbrain/dokuwiki/issues/1056

  • https://github.com/splitbrain/dokuwiki/commit/4970ad24ce49ec76a0ee67bca7594f918ced2f5f

EPSS

Процентиль: 82%
0.01762
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

nvd
почти 11 лет назад

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

github
больше 3 лет назад

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

EPSS

Процентиль: 82%
0.01762
Низкий