CVE Vulnerabilities

CVE-2010-0288

Published: Feb 15, 2010 | Modified: Sep 23, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

Affected Software

Name Vendor Start Version End Version
Dokuwiki Dokuwiki * release_2009-02-14 (including)
Dokuwiki Dokuwiki 2004-07-04 (including) 2004-07-04 (including)
Dokuwiki Dokuwiki 2004-07-07 (including) 2004-07-07 (including)
Dokuwiki Dokuwiki 2004-07-12 (including) 2004-07-12 (including)
Dokuwiki Dokuwiki 2004-07-21 (including) 2004-07-21 (including)
Dokuwiki Dokuwiki 2004-07-25 (including) 2004-07-25 (including)
Dokuwiki Dokuwiki 2004-08-08 (including) 2004-08-08 (including)
Dokuwiki Dokuwiki 2004-08-15a (including) 2004-08-15a (including)
Dokuwiki Dokuwiki 2004-08-22 (including) 2004-08-22 (including)
Dokuwiki Dokuwiki 2004-09-12 (including) 2004-09-12 (including)
Dokuwiki Dokuwiki 2004-09-25 (including) 2004-09-25 (including)
Dokuwiki Dokuwiki 2004-09-30 (including) 2004-09-30 (including)
Dokuwiki Dokuwiki 2004-11-01 (including) 2004-11-01 (including)
Dokuwiki Dokuwiki 2004-11-02 (including) 2004-11-02 (including)
Dokuwiki Dokuwiki 2004-11-10 (including) 2004-11-10 (including)
Dokuwiki Dokuwiki 2005-01-14 (including) 2005-01-14 (including)
Dokuwiki Dokuwiki 2005-01-15 (including) 2005-01-15 (including)
Dokuwiki Dokuwiki 2005-01-16a (including) 2005-01-16a (including)
Dokuwiki Dokuwiki 2005-02-06 (including) 2005-02-06 (including)
Dokuwiki Dokuwiki 2005-02-18 (including) 2005-02-18 (including)
Dokuwiki Dokuwiki 2005-05-07 (including) 2005-05-07 (including)
Dokuwiki Dokuwiki 2005-07-01 (including) 2005-07-01 (including)
Dokuwiki Dokuwiki 2005-07-13 (including) 2005-07-13 (including)
Dokuwiki Dokuwiki 2005-09-19 (including) 2005-09-19 (including)
Dokuwiki Dokuwiki 2005-09-22 (including) 2005-09-22 (including)
Dokuwiki Dokuwiki 2006-03-05 (including) 2006-03-05 (including)
Dokuwiki Dokuwiki 2006-03-09 (including) 2006-03-09 (including)
Dokuwiki Dokuwiki 2006-03-09e (including) 2006-03-09e (including)
Dokuwiki Dokuwiki 2006-06-04 (including) 2006-06-04 (including)
Dokuwiki Ubuntu artful *
Dokuwiki Ubuntu dapper *
Dokuwiki Ubuntu hardy *
Dokuwiki Ubuntu intrepid *
Dokuwiki Ubuntu jaunty *
Dokuwiki Ubuntu karmic *
Dokuwiki Ubuntu lucid *
Dokuwiki Ubuntu maverick *
Dokuwiki Ubuntu natty *
Dokuwiki Ubuntu oneiric *
Dokuwiki Ubuntu precise *
Dokuwiki Ubuntu quantal *
Dokuwiki Ubuntu raring *
Dokuwiki Ubuntu saucy *
Dokuwiki Ubuntu upstream *
Dokuwiki Ubuntu utopic *
Dokuwiki Ubuntu vivid *
Dokuwiki Ubuntu wily *
Dokuwiki Ubuntu yakkety *
Dokuwiki Ubuntu zesty *

References