Information disclosure in DokuWiki - CVE-2012-3354

 

Information disclosure in DokuWiki - CVE-2012-3354

Published: November 20, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43324
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-3354
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.


Affected software

DokuWiki
Fedora
dokuwiki

How to mitigate CVE-2012-3354

Install update from vendor's website.

dokuwiki - addressed in versions 0-0.10.20120125.b.el6, 0-0.12.20120125.b.el5, 0-0.14.20121013.el5, 0-0.14.20121013.el6

External References

Related Security Bulletins