Main
Vulnerability Database
Exploits
ID:1148 - Exploit for Improper access control in DokuWiki - CVE-2010-0288
ID:1148 - Exploit for Improper access control in DokuWiki - CVE-2010-0288
Published: March 18, 2020
Vulnerability identifier: #VU6180
Vulnerability risk: Low
CVE-ID: CVE-2010-0288
CWE-ID: CWE-284
Exploitation vector: Remote access
Vulnerable software:
DokuWiki
DokuWiki
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass implemented access controls.
The vulnerability exists due to a typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b. A remote attacker can access closed wikis by editing current ACL statements.
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to the website.
The vulnerability exists due to a typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b. A remote attacker can access closed wikis by editing current ACL statements.
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to the website.