Security Update for DokuWiki
The 2009-02-14b update for the DokuWiki Wiki System eliminates a vulnerability which could allow an attacker to compromise a vulnerable system. The config_cascade Parameters in inc/init.php were un-verified, allowing a PHP script to be inserted and run.
The published exploit shows how local files can be exploited, but should also work for external sites. For an attack to be successful, the PHP register_globals option must be enabled.
(dab)
(crve)
![Kernel Log: Coming in 3.10 (Part 3) [--] Infrastructure](/imgs/43/1/0/4/2/6/7/2/comingin310_4_kicker-4977194bfb0de0d7.png)

![Kernel Log: Coming in 3.10 (Part 3) [--] Infrastructure](/imgs/43/1/0/4/2/3/2/3/comingin310_3_kicker-151cd7b9e9660f05.png)
















