CVE-2006-2878

Publication date 7 June 2006

Last updated 17 July 2025


Ubuntu priority

Description

The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.

Status

Package Ubuntu Release Status
dokuwiki 9.10 karmic
Fixed 0.0.20060309-4
9.04 jaunty
Fixed 0.0.20060309-4
8.10 intrepid
Fixed 0.0.20060309-4
8.04 LTS hardy
Fixed 0.0.20060309-4
7.10 gutsy
Fixed 0.0.20060309-4
7.04 feisty
Fixed 0.0.20060309-4
6.10 edgy
Fixed 0.0.20060309-4
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities