CVE-2006-4674

Source
https://cve.org/CVERecord?id=CVE-2006-4674
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2006-4674.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2006-4674
Downstream
Withdrawn
2026-01-27T04:06:47.635751Z
Published
2006-09-11T17:04:00Z
Modified
2026-01-27T04:06:47.635751Z
Summary
[none]
Details

Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.

References

Affected packages