CVE-2010-0288

high
Published 2010-02-15 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.5

Description

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-11141 webapps php verified
IHTeam ยท 2010-01-14

dokuwiki 2009-12-25 - Multiple Vulnerabilities

Source code queued for fetch โ€” refresh in a moment.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.0.20090214b-3.1
sid Fixed 0.0.20090214b-3.1
forky Fixed 0.0.20090214b-3.1
bullseye Fixed 0.0.20090214b-3.1
bookworm Fixed 0.0.20090214b-3.1

Application impact

VendorProductVersionsFixed
dokuwikidokuwiki{"endIncluding":"release_2009-02-14"}
dokuwikidokuwiki2004-07-04
dokuwikidokuwiki2004-07-07
dokuwikidokuwiki2004-08-15a
dokuwikidokuwiki2004-08-22
dokuwikidokuwiki2004-07-21
dokuwikidokuwiki2004-07-25
dokuwikidokuwiki2004-07-12
dokuwikidokuwiki2004-08-08
dokuwikidokuwiki2005-02-06
dokuwikidokuwiki2005-02-18
dokuwikidokuwiki2005-05-07
dokuwikidokuwiki2005-07-01
dokuwikidokuwiki2005-07-13
dokuwikidokuwiki2005-09-19
dokuwikidokuwiki2005-09-22
dokuwikidokuwiki2006-03-05
dokuwikidokuwiki2006-03-09
dokuwikidokuwiki2006-03-09e
dokuwikidokuwiki2006-06-04
dokuwikidokuwiki2004-09-12
dokuwikidokuwiki2004-09-25
dokuwikidokuwiki2004-09-30
dokuwikidokuwiki2004-11-01
dokuwikidokuwiki2004-11-02
dokuwikidokuwiki2004-11-10
dokuwikidokuwiki2005-01-14
dokuwikidokuwiki2005-01-15
dokuwikidokuwiki2005-01-16a

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.