[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2366-1 mediawiki -- multiple

ID: oval:org.secpod.oval:def:600666Date: (C)2012-01-30   (M)2023-11-09
Class: PATCHFamily: unix




Several problems have been discovered in mediawiki, a website engine for collaborative work. CVE-2011-1578 CVE-2011-1587 Masato Kinugawa discovered a cross-site scripting issue, which affects Internet Explorer clients only, and only version 6 and earlier. Web server configuration changes are required to fix this issue. Upgrading MediaWiki will only be sufficient for people who use Apache with AllowOverride enabled. This is an XSS issue for Internet Explorer clients, and a privacy loss issue for other clients since it allows the embedding of arbitrary remote images. CVE-2011-1580 MediaWiki developer Happy-Melon discovered that the transwiki import feature neglected to perform access control checks on form submission. The transwiki import feature is disabled by default. If it is enabled, it allows wiki pages to be copied from a remote wiki listed in $wgImportSources. The issue means that any user can trigger such an import to occur. CVE-2011-4360 Alexandre Emsenhuber discovered an issue where page titles on private wikis could be exposed bypassing different page ids to index.php. In the case of the user not having correct permissions, they will now be redirected to Special:BadTitle. CVE-2011-4361 Tim Starling discovered that action=ajax requests were dispatched to the relevant function without any read permission checks being done. This could have led to data leakage on private wikis.

Platform:
Debian 5.0
Debian 6.0
Product:
mediawiki
Reference:
DSA-2366-1
CVE-2011-1578
CVE-2011-1579
CVE-2011-1580
CVE-2011-1587
CVE-2011-4360
CVE-2011-4361
CVE    6
CVE-2011-1580
CVE-2011-1587
CVE-2011-1579
CVE-2011-1578
...
CPE    139
cpe:/a:mediawiki:mediawiki:1.16.2
cpe:/o:debian:debian_linux:6.x
cpe:/a:mediawiki:mediawiki:1.12.3
cpe:/a:mediawiki:mediawiki:1.4:beta4
...

© SecPod Technologies