News Feed
Jobs Feed
Sections




News Archive
Stefan Esser's Blog:
DokuWiki remote PHP code injection
June 05, 2006 @ 06:08:12

Stefan Esser has posted this new security issue he discovered in the DokuWiki application.

While searching for the perfect Wiki PHP application for my own german/korean wiki I tested DokuWiki and found an ugly security hole, that allows remote PHP code injection through it's AJAX spellchecking service.

You can read up on his full advisory here, including the location/code of the issue.

0 comments voice your opinion now!
remote injection security advisory dokuwiki remote injection security advisory dokuwiki


blog comments powered by Disqus

Similar Posts

Rochak Chauhan's Blog: Top Ten Security Vulnerabilities in PHP Code

Chris Shiflett\'s Blog: PHP Insecurity

PHP.net: PHP 4.4.3 Released

Project: RIPS - Static Source Code Analyzer for Vulnerabilities in PHP Scripts

CodePoets.co.uk: How to use PHP and PEAR MDB2 (Tutorial)


Community Events











Don't see your event here?
Let us know!


podcast example application zendframework2 api release interview development series database composer phpunit community introduction testing framework functional opinion code language

All content copyright, 2013 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework