CVE-2017-18123: Input Validation
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18123?
CVE-2017-18123 has a medium severity rating that indicates it poses a risk of reflected file download exploitation.
How do I fix CVE-2017-18123?
To fix CVE-2017-18123, update DokuWiki to a version later than 2017-02-19e that includes the necessary security patches.
What software is affected by CVE-2017-18123?
CVE-2017-18123 affects DokuWiki versions up to and including 2017-02-19e and Debian Linux version 7.0.
What type of vulnerability is CVE-2017-18123?
CVE-2017-18123 is classified as a reflected file download vulnerability that allows attackers to execute arbitrary programs remotely.
Can CVE-2017-18123 lead to data breaches?
Yes, CVE-2017-18123 could potentially lead to data breaches by allowing unauthorized execution of commands on a vulnerable system.