|
|
| |
| DokuWiki is "a simple to use Wiki aimed at a small companies documentation needs". A vulnerability in the way DokuWiki handles user provided input allows remote attackers to cause the product to insert arbitrary HTML and/or JavaScript into the responses it sends back, allowing attackers to trigger a XSS vulnerability. |
| |
Credit:
The information has been provided by unsticky.
|
| |
Example URL:
The following URL will trigger the vulnerability:
http://[site.com]/[dokuwiki]/lib/exe/fetch.php?media=http://%0d%0a%0d%0a %3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E
|
|
|