Description
DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".
Affected products
- andreas_gohr / dokuwikirelease_2004-07-04 – release_2004-07-04
- andreas_gohr / dokuwikirelease_2004-07-07 – release_2004-07-07
- andreas_gohr / dokuwikirelease_2004-07-12 – release_2004-07-12
- andreas_gohr / dokuwikirelease_2004-07-21 – release_2004-07-21
- andreas_gohr / dokuwikirelease_2004-07-25 – release_2004-07-25
- andreas_gohr / dokuwikirelease_2004-08-08 – release_2004-08-08
- andreas_gohr / dokuwikirelease_2004-08-15a – release_2004-08-15a
- andreas_gohr / dokuwikirelease_2004-08-22 – release_2004-08-22
- andreas_gohr / dokuwikirelease_2004-09-12 – release_2004-09-12
- andreas_gohr / dokuwikirelease_2004-09-25 – release_2004-09-25
- andreas_gohr / dokuwikirelease_2004-09-30 – release_2004-09-30