CVE-2006-2878
EPSS 4.4%
Description
The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.
How to fix CVE-2006-2878
To remediate CVE-2006-2878, upgrade the affected package to a fixed version below.
- Debian/dokuwiki—upgrade to 0.0.20060309-4 or later
Is CVE-2006-2878 being exploited?
Low — EPSS is 4.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.0.20060309-4