Security of community developed and 3rd-party wiki plug-ins

  • Authors:
  • Andy Webber

  • Affiliations:
  • Oracle Corporation, Reading, United Kingdom

  • Venue:
  • WikiSym '08 Proceedings of the 4th International Symposium on Wikis
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper discusses the significant security vulnerabilities that can occur in community developed wiki plug-ins and issues associated with managing the process of remediation. General guidance is given on how the vulnerabilities can be detected and rectified. The basis for the paper is direct experience with a number of community developed plug-ins for DokuWiki, although the findings have also been transferred to other wikis such as MediaWiki. The findings are also transferable to other similar web server technologies - such as blogs - that support similar plug-in frameworks.