First published: Fri Dec 31 2004(Updated: )
DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =release_2004-07-07 | |
DokuWiki | =release_2004-08-08 | |
DokuWiki | =release_2004-09-12 | |
DokuWiki | =release_2004-07-25 | |
DokuWiki | =release_2004-08-22 | |
DokuWiki | =release_2004-09-25 | |
DokuWiki | =release_2004-07-04 | |
DokuWiki | =release_2004-07-21 | |
DokuWiki | =release_2004-09-30 | |
DokuWiki | =release_2004-08-15a | |
DokuWiki | =release_2004-07-12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2559 is considered a medium severity vulnerability due to potential unauthorized access to administrative functionalities.
To fix CVE-2004-2559, upgrade DokuWiki to a version released after October 19, 2004.
CVE-2004-2559 affects DokuWiki versions released from July 4, 2004, to October 19, 2004.
CVE-2004-2559 exposes functionalities such as the Mediaselectiondialog, Recent changes, feed, and search.
Users of DokuWiki versions prior to October 19, 2004, are at risk of unauthorized administrative access due to CVE-2004-2559.