← All CVEs

CVE-2009-1960

high · 9.3

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

9.3
CVSS
23.2%
EPSS (exploit prob.)
98th
EPSS percentile
2009-06-08
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
dokuwikidokuwiki2009-02-14
dokuwikidokuwikirc2009-01-30
dokuwikidokuwikirc2009-02-06

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1960