CVE-2010-0287
DokuWiki < 2009-12-25b - Directory Traversal via ACL Manager ns Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0287. PoCs published by IHTeam.
AI-analyzed exploit summary This exploit demonstrates directory traversal and unauthorized ACL manipulation in DokuWiki's ACL plugin. It allows listing arbitrary file names and modifying wiki permissions without proper authentication.
Description
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.
Exploits (1)
This exploit demonstrates directory traversal and unauthorized ACL manipulation in DokuWiki's ACL plugin. It allows listing arbitrary file names and modifying wiki permissions without proper authentication.