First published: Mon Jan 29 2007(Updated: )
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =release_2006-03-09 | |
DokuWiki | =release_2006-03-09e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6965 is considered a high severity vulnerability due to its potential for allowing HTTP response splitting attacks.
To fix CVE-2006-6965, update DokuWiki to a version released after 2006-03-09e that addresses this vulnerability.
CVE-2006-6965 affects DokuWiki versions 2006-03-09 and 2006-03-09e.
Yes, CVE-2006-6965 can be leveraged to conduct XSS attacks due to HTTP header injection.
The potential impacts of CVE-2006-6965 include unauthorized data access and manipulation through crafted HTTP headers.