// For flags

CVE-2006-5099

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert.

lib/exec/fetch.php en DokuWiki anterior a 09/03/2006, cuando se configura conf[imconvert] para usar ImageMagick, permite a un atacante remoto ejecutar comandos de su elección a través de los metacaracteres del interprete de comandos en los parámetros (1)w y (2) h, los cuales no fueron filtrados cuando se invocó la conversión.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-09-29 CVE Reserved
  • 2006-09-29 CVE Published
  • 2024-06-04 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Andreas Gohr
Search vendor "Andreas Gohr"
Dokuwiki
Search vendor "Andreas Gohr" for product "Dokuwiki"
release_2006-03-05
Search vendor "Andreas Gohr" for product "Dokuwiki" and version "release_2006-03-05"
-
Affected
Andreas Gohr
Search vendor "Andreas Gohr"
Dokuwiki
Search vendor "Andreas Gohr" for product "Dokuwiki"
release_2006-03-09
Search vendor "Andreas Gohr" for product "Dokuwiki" and version "release_2006-03-09"
-
Affected
Andreas Gohr
Search vendor "Andreas Gohr"
Dokuwiki
Search vendor "Andreas Gohr" for product "Dokuwiki"
release_2006-03-09e
Search vendor "Andreas Gohr" for product "Dokuwiki" and version "release_2006-03-09e"
-
Affected