Mandriva Linux Security Advisory : dokuwiki (MDVSA-2013:073)

Medium Nessus Plugin ID 66087


The remote Mandriva Linux host is missing a security update.


Updated dokuwiki package fixes security vulnerabilities :

DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files (CVE-2011-3727).

A full path disclosure flaw was found in the way DokuWiki, a standards compliant, simple to use Wiki, performed sanitization of HTTP POST 'prefix' input value prior passing it to underlying PHP substr() routine, when the PHP error level has been enabled on the particular server. A remote attacker could use this flaw to obtain full path location of particular requested DokuWiki page by issuing a specially crafted HTTP POST request (CVE-2012-3354).


Update the affected dokuwiki package.

Plugin Details

Severity: Medium

ID: 66087

File Name: mandriva_MDVSA-2013-073.nasl

Version: $Revision: 1.5 $

Type: local

Published: 2013/04/20

Modified: 2016/05/17

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:dokuwiki, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2013/04/08

Reference Information

CVE: CVE-2011-3727, CVE-2012-3354

BID: 56327, 56328

MDVSA: 2013:073

MGASA: 2012-0362