CVE-2010-0288
IN THE WILDDokuWiki < 2009-12-25b - Unauthenticated Privilege Escalation via ACL Manager Plugin
Title source: llmExploitation Summary
CVE-2010-0288 has been observed exploited in the wild (reported by InTheWild.io). EIP tracks 1 public exploit from researchers including IHTeam.
AI-analyzed exploit summary This exploit demonstrates directory traversal and unauthorized ACL manipulation in DokuWiki's ACL plugin. It allows listing arbitrary file names and modifying wiki permissions without proper authentication.
Description
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.
Exploits (1)
This exploit demonstrates directory traversal and unauthorized ACL manipulation in DokuWiki's ACL plugin. It allows listing arbitrary file names and modifying wiki permissions without proper authentication.