VDB
CVE-2006-2878
CVE-2006-2878
PUBLISHED
CVSS 7.5 HIGH
The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.
EPSS 13.92% · 96.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
13.92%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| andreas_gohr | dokuwiki | release_2004-07-04, release_2004-07-07, release_2004-07-12 |
Timeline
- Jun 7, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Apr 10, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://www.osvdb.org/25980 url
- 18289 vdb
- 20060605 Advisory 04/2006: DokuWiki PHP code execution vulnerability in spellchecker mailing-list
- ADV-2006-2142 vdb
- http://www.hardened-php.net/advisory_042006.119.html url
- dokuwiki-spellchecker-code-execution(26913) vdb
- GLSA-200606-16 vendor-advisory
- http://bugs.splitbrain.org/index.php?do=details&id=823 url
- 1016221 vdb
- 20429 third-party-advisory
- 20060605 Advisory 04/2006: DokuWiki PHP code execution vulnerability in spellchecker mailing-list
- 20669 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-2878 advisory