Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dokuwiki | Jul 30, 2024 | Sep 11, 2006 |
| Freebsd | — | Upgrade dokuwikiUpgrade dokuwiki-devel | Dec 10, 2025 | Sep 30, 2006 |
| Gentoo Linux | — | Upgrade www-apps/dokuwiki. | Oct 30, 2017 | Sep 11, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub