CVE-2011-3727
Publication date 23 September 2011
Last updated 24 July 2024
Ubuntu priority
Description
DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| dokuwiki | 25.10 questing |
Vulnerable
|
| 25.04 plucky |
Vulnerable
|
|
| 24.04 LTS noble |
Vulnerable
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Vulnerable
|
|
| 18.04 LTS bionic |
Vulnerable
|
|
| 16.04 LTS xenial |
Vulnerable
|
|
| 14.04 LTS trusty | Not in release | |
Notes
tyhicks
Minimal diff between lib/tpl/index.php in 0.0.20091225c-3 and 0.0.20110525a-2, so I'm marking oneiric as needed.