News Feed

News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Stefan Esser's Blog:
DokuWiki remote PHP code injection
June 05, 2006 @ 06:08:12

Stefan Esser has posted this new security issue he discovered in the DokuWiki application.

While searching for the perfect Wiki PHP application for my own german/korean wiki I tested DokuWiki and found an ugly security hole, that allows remote PHP code injection through it's AJAX spellchecking service.

You can read up on his full advisory here, including the location/code of the issue.

0 comments voice your opinion now!
remote injection security advisory dokuwiki remote injection security advisory dokuwiki

blog comments powered by Disqus

Similar Posts SQL Injections in PHP with MySQL

DevShed: PHP Programs to Prevent MySQL Injection or HTML Form Abuse

Ben Ramsey\'s Blog: Peruser MPM for Apache

Smashing Magazine: Keeping Web Users Safe By Sanitizing Input Data

Think-PHP Blog: Detect and fix security vulnerabilities on server side within seconds

Community Events

Don't see your event here?
Let us know!

version community api release podcast zendserver tips conference list introduction developer laravel application development deployment framework code language interview series

All content copyright, 2014 :: - Powered by the Solar PHP Framework