DokuWiki

This is the issue tracking system for DokuWiki. You may add bugs and feature wishes here.

Please post support requests and plugin wishes in the forum. Bug reports for plugins should be reported in the plugin's tracker linked from the plugin page.

To prevent spamming anonymous task adding had to be disabled.
Tasklist

FS#1847 - show outside directory

Attached to Project: DokuWiki
Opened by white (white_sheep) - Wednesday, 13 January 2010, 02:12 GMT+2
Last edited by Andreas Gohr (andi) - Wednesday, 13 January 2010, 18:53 GMT+2
Task Type Bug Report
Category Security
Status Closed
Assigned To No-one
Operating System All
Severity High
Priority Normal
Reported Version 2009-12-25 "Lemming"
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

hello,
i found this bug that show me outside directory.
A PoC is:

http://localhost/plugins/acl/ajax.php?ajax=tree&ns=../pages/


please fix asap

i will publish it after 30 days from now.

if you need more information contact me.

regards

white_sheep - IHTeam Staff
This task depends upon

Closed by  Andreas Gohr (andi)
Wednesday, 13 January 2010, 18:53 GMT+2
Reason for closing:  Fixed
Additional comments about closing:  fixed in 2009-12-25b
Comment by Andreas Gohr (andi) - Wednesday, 13 January 2010, 18:50 GMT+2
The bug allows listing the names of arbitrary file on the webserver - not their contents. This could leak private information about wiki pages and server structure.

A hotfix named 2009-12-25b was released and can be downloaded at http://www.splitbrain.org/go/dokuwiki

If you want to manually fix the flaw, replace the ACL Manager plugin in lib/plugins/acl/ with the version available at http://www.dokuwiki.org/_media/plugin:acl-plugin.tgz and increase the number in conf/msg to 24.
Comment by Andreas Gohr (andi) - Friday, 15 January 2010, 10:32 GMT+2
Because of a typo in the administrator permission check this bug also affects editing the current ACL statements, allowing an attacker to introduce arbitrary ACL rules and thus gaining access to a closed Wiki. An exploit was seen in the wild and upgrading to the version mentioned or applying the manual fix above is highly recommended.
Comment by Andreas Gohr (andi) - Sunday, 17 January 2010, 11:51 GMT+2
Please also see  FS#1853 

Loading...

WikiForumIRCBugsGitXRefTranslate