CVE-2017-18123: Debian Linux
High severity, CVSS 8.6. EPSS: 2.6% chance of exploitation in the next 30 days.
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
Affected products
Published 2018-02-03. Last modified 2026-06-17.