Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0288

Опубликовано: 15 фев. 2010
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:*
Версия до release_2009-02-14 (включая)
cpe:2.3:a:dokuwiki:dokuwiki:2004-07-04:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-07-07:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-07-12:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-07-21:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-07-25:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-08-08:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-08-15a:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-08-22:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-09-12:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-09-25:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-09-30:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-11-01:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-11-02:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2004-11-10:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-01-14:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-01-15:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-01-16a:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-02-06:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-02-18:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-05-07:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-07-01:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-07-13:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-09-19:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2005-09-22:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-03-05:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-03-09:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-03-09e:*:*:*:*:*:*:*
cpe:2.3:a:dokuwiki:dokuwiki:2006-06-04:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15608
Средний

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 16 лет назад

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

redhat
почти 16 лет назад

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

debian
почти 16 лет назад

A typo in the administrator permission check in the ACL Manager plugin ...

github
больше 3 лет назад

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

EPSS

Процентиль: 94%
0.15608
Средний

7.5 High

CVSS2

Дефекты

CWE-264