CVE-2017-18123 is a reflected file download vulnerability in DokuWiki through version 2017-02-19e, specifically within the /lib/exe/ajax.php script due to improper encoding of the 'call' parameter. This vulnerability affects various DokuWiki installations, including those on Debian Linux. With a CVSS score of 8.6 (HIGH), it allows remote attackers to execute arbitrary programs on a user's system, requiring user interaction but with low attack complexity and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2017-02-19eCPE matchmatch criteria | cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.