VDB

GCVE-110-MAGEIA-2014-540

GCVE-110-MAGEIA-2014-540
Advisory Published
Vulnetix · Advisory published December 19, 2014
Updated dokuwiki package fix a security vulnerability: Our current dokuwiki-20140929-1.1.mga4 package uses dokuwiki-2014-09-29a source which allows swf (application/x-shockwave-flash) uploads by default. This may be used for Cross-site scripting (XSS) attack which enables attackers to inject client-side script into Web pages viewed by other users. (CVE-2014-9253). This update uses dokuwiki-2014-09-29b hotfix source which disables swf uploads by default and fixes the issue.

Affected Products

VendorProductVersionsPlatforms
Mageiadokuwiki0 (affected), 20140929-1.2.mga4 (unaffected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›