CVE-2017-18123: Debian Linux

High severity, CVSS 8.6. EPSS: 2.6% chance of exploitation in the next 30 days.

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Dokuwiki Dokuwiki: up to and including 2017-02-19e

Published 2018-02-03. Last modified 2026-06-17.