First published: Fri Dec 31 2004(Updated: )
DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =release_2004-07-07 | |
DokuWiki | =release_2004-08-08 | |
DokuWiki | =release_2004-09-12 | |
DokuWiki | =release_2004-07-25 | |
DokuWiki | =release_2004-08-22 | |
DokuWiki | =release_2004-09-25 | |
DokuWiki | =release_2004-07-04 | |
DokuWiki | =release_2004-07-21 | |
DokuWiki | =release_2004-09-30 | |
DokuWiki | =release_2004-08-15a | |
DokuWiki | =release_2004-07-12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2560 is classified as a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2004-2560, upgrade to a version of DokuWiki released after October 19, 2004.
DokuWiki versions before 2004-10-19 are affected by CVE-2004-2560.
Yes, CVE-2004-2560 can be exploited remotely by uploading files with executable extensions.
Files with extensions such as ".php" and ".cgi" can be used to exploit CVE-2004-2560.