VDB

CVE-2016-7964

CVE-2016-7964 PUBLISHED CVSS 8.600000381469727 HIGH

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

EPSS 1.49% · 72.1th percentile

Risk Scores

CVSS 3.0
8.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score
1.49%
72.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSdokuwiki0, 0.0.20160626.a-2
Ubuntu:16.04:LTSdokuwiki0, 0.0.20140929.d-1, 0.0.20140929.d-1ubuntu1

Timeline

  • Oct 31, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›