S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-12583 Scanner

CVE-2017-12583 scanner - Cross-Site Scripting (XSS) vulnerability in DokuWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-12583
6.1
CVSS

DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

DokuWiki is an open-source software that allows users to easily manage and collaborate on the creation of documentation, such as wikis, FAQs, and manuals. It is used by companies, organizations, and individuals to create and organize their knowledge and information in a centralized location that is easily accessible to their teams. DokuWiki is designed to be simple and flexible, allowing users to easily customize its features and functionality to meet their specific needs.

The CVE-2017-12583 vulnerability detected in DokuWiki through 2017-02-19b is related to XSS (cross-site scripting) in the at parameter or DATE_AT variable to doku.php. This vulnerability can be exploited by attackers to inject malicious scripts or content into a webpage that is accessed by users of the affected software. It is important to note that this vulnerability can only be exploited by attackers who have access to the system or network where DokuWiki is installed.

When exploited, the CVE-2017-12583 vulnerability can lead to theft of sensitive information, unauthorized access to data, and the compromise of the entire system or network. Attackers can gain access to sensitive information by injecting malicious scripts or content into webpages and capturing user data, such as login credentials, credit card information, and other personally identifiable information. They can also use this vulnerability to gain administrative access to the system or network, giving them the ability to execute commands and take control of the affected systems.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability assessment and management tools that can help protect against the latest security threats. With s4e.io, users can easily stay up-to-date on the latest security vulnerabilities and take proactive steps to protect their systems, networks, and digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of DokuWiki should take the following precautions:

  • Upgrade to the latest version of DokuWiki which includes a fix for the vulnerability
  • Implement strict access controls and permissions on the DokuWiki installation to limit the access of potential attackers
  • Use secure coding practices to prevent the injection of malicious scripts or content into webpages
  • Use a web application firewall or other security software to detect and block malicious requests
  • Conduct regular security audits and vulnerability scans of the system or network to identify any potential weaknesses or vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-12583 scanner - Cross-Site Scripting (XSS) vulnerability in DokuWiki | S4E