CVE-2009-1960
Publication date 8 June 2009
Last updated 24 July 2024
Ubuntu priority
Description
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| dokuwiki | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |