CVE-2004-2560 Information

Description

DokuWiki before 2004-10-19 when used on a web server that permits execution based on file extension allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as .php\ or .cgi.

Reference

http://wiki.splitbrain.org/wiki:old_changes http://www.osvdb.org/11084 http://www.securityfocus.com/bid/11486 https://exchange.xforce.ibmcloud.com/vulnerabilities/17899

Share on: