The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94245 | Third Party Advisory VDB Entry |
https://github.com/splitbrain/dokuwiki/issues/1708 | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2016-10-31T10:00:00
Updated: 2016-11-25T19:57:01
Reserved: 2016-09-09T00:00:00
Link: CVE-2016-7964
JSON object: View
NVD Information
Status : Analyzed
Published: 2016-10-31T10:59:00.177
Modified: 2016-12-02T23:09:07.337
Link: CVE-2016-7964
JSON object: View
Redhat Information
No data.
CWE