CVE-2006-6965: XSS
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6965?
CVE-2006-6965 is considered a high severity vulnerability due to its potential for allowing HTTP response splitting attacks.
How do I fix CVE-2006-6965?
To fix CVE-2006-6965, update DokuWiki to a version released after 2006-03-09e that addresses this vulnerability.
What systems are affected by CVE-2006-6965?
CVE-2006-6965 affects DokuWiki versions 2006-03-09 and 2006-03-09e.
Can CVE-2006-6965 be exploited for XSS attacks?
Yes, CVE-2006-6965 can be leveraged to conduct XSS attacks due to HTTP header injection.
What are the potential impacts of CVE-2006-6965?
The potential impacts of CVE-2006-6965 include unauthorized data access and manipulation through crafted HTTP headers.