CVE: CVE-2006-2878

Export to Word

The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.04385
Percentile: 0.88506

CVSS Scoring

CVSS v2 Score: 7.5

Severity:

Affected Products

← Back to Home