PoC Index

CVE-2009-1960

HIGH 9.3EPSS 23.2%

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
23.16% chance of exploitation in the next 30 days, 98th percentile
Published
2009-06-06
Updated
2024-08-07

ExploitDB entries (2)

References

Related