CVE-2006-1165: XSS
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1165?
CVE-2006-1165 has been classified with a severity rating that indicates it poses a moderate risk due to its ability to facilitate cross-site scripting attacks.
How do I fix CVE-2006-1165?
To fix CVE-2006-1165, update your DokuWiki installation to version 2006-03-05 or later, which addresses the XSS vulnerability.
What type of vulnerability is CVE-2006-1165?
CVE-2006-1165 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Which versions of DokuWiki are affected by CVE-2006-1165?
CVE-2006-1165 affects all DokuWiki versions prior to 2006-03-05.
What can attackers do with CVE-2006-1165?
Attackers exploiting CVE-2006-1165 can inject malicious scripts into web pages viewed by users, potentially compromising their session or stealing sensitive information.