First published: Fri Sep 29 2006(Updated: )
lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =release_2006-03-05 | |
DokuWiki | =release_2006-03-09 | |
DokuWiki | =release_2006-03-09e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5099 is considered a high severity vulnerability due to its ability to allow remote command execution.
To fix CVE-2006-5099, update DokuWiki to a version released after 2006-03-09e or reconfigure the imconvert parameter to eliminate the threat.
The potential impacts of CVE-2006-5099 include unauthorized command execution, which could compromise system security.
CVE-2006-5099 affects DokuWiki versions up to and including release 2006-03-09e.
If an update cannot be applied, disabling the use of ImageMagick for image processing can serve as a temporary workaround for CVE-2006-5099.