From a9f3ecaa448a3d1dd569dd38237f37701e603d0e Mon Sep 17 00:00:00 2001 From: Xin LI Date: Mon, 23 Apr 2012 23:41:12 +0000 Subject: [PATCH] Document dokuwiki CSRF vulnerability. --- security/vuxml/vuln.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 005d9ff5ce25..de7f6f19488e 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -52,6 +52,32 @@ Note: Please add new entries to the beginning of this file. --> + + Dokuwiki -- cross site scripting vulnerability + + + dokuwiki + 20120125_1 + + + + +

Andy Webber reports:

+
+

Add User appears to be vulnerable to Cross Site Request Forgery (CSRF/XSRF).

+
+ +
+ + CVE-2012-2128 + CVE-2012-2129 + + + 2012-04-17 + 2012-04-23 + +
+ asterisk -- multiple vulnerabilities