CVE-2006-5099: High severity andreas gohr dokuwiki vulnerability
lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5099?
CVE-2006-5099 is considered a high severity vulnerability due to its ability to allow remote command execution.
How do I fix CVE-2006-5099?
To fix CVE-2006-5099, update DokuWiki to a version released after 2006-03-09e or reconfigure the imconvert parameter to eliminate the threat.
What are the potential impacts of CVE-2006-5099?
The potential impacts of CVE-2006-5099 include unauthorized command execution, which could compromise system security.
Which versions of DokuWiki are affected by CVE-2006-5099?
CVE-2006-5099 affects DokuWiki versions up to and including release 2006-03-09e.
Is there a workaround for CVE-2006-5099 if I cannot update?
If an update cannot be applied, disabling the use of ImageMagick for image processing can serve as a temporary workaround for CVE-2006-5099.