Total vulnerabilities in the database
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
Software | From | Fixed in |
---|---|---|
dokuwiki / dokuwiki | - | 2014-05-05a.x |
mageia_project / mageia | 3.0 | 3.0.x |
mageia_project / mageia | 4.0 | 4.0.x |