← Back

CVE-2009-1960

nvd nist
Published: Jun 8, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

Affected (3)

Products: Dokuwiki: Dokuwiki
1 product
Dokuwiki
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Dokuwiki
Version 2009-02-14
Version rc2009-01-30
Version rc2009-02-06

Timeline

No history available yet.