MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
BID:12305
Info
MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
| Bugtraq ID: | 12305 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2005 12:00AM |
| Updated: | Jan 18 2005 12:00AM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
MediaWiki MediaWiki 1.4 beta4 MediaWiki MediaWiki 1.4 beta3 MediaWiki MediaWiki 1.4 beta2 MediaWiki MediaWiki 1.4 beta1 |
| Not Vulnerable: |
MediaWiki MediaWiki 1.4 beta5 |
Discussion
MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
MediaWiki is reported prone to multiple remote code execution vulnerabilities. These issues may allow an attacker gain unauthorized access to a vulnerable computer by executing arbitrary PHP code.
Further details are not currently available, however, it is conjectured that this issue may allow for file include or arbitrary command execution type attacks.
MediaWiki versions 1.4 beta1 to 1.4 beta4 are affected by this issue.
MediaWiki is reported prone to multiple remote code execution vulnerabilities. These issues may allow an attacker gain unauthorized access to a vulnerable computer by executing arbitrary PHP code.
Further details are not currently available, however, it is conjectured that this issue may allow for file include or arbitrary command execution type attacks.
MediaWiki versions 1.4 beta1 to 1.4 beta4 are affected by this issue.
Exploit / POC
MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
Solution:
The vendor has released MediaWiki 1.4beta5 to address these issues.
MediaWiki MediaWiki 1.4 beta3
MediaWiki MediaWiki 1.4 beta2
MediaWiki MediaWiki 1.4 beta1
MediaWiki MediaWiki 1.4 beta4
Solution:
The vendor has released MediaWiki 1.4beta5 to address these issues.
MediaWiki MediaWiki 1.4 beta3
-
MediaWiki mediawiki-1.4beta5.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4beta5.tar.gz ?download
MediaWiki MediaWiki 1.4 beta2
-
MediaWiki mediawiki-1.4beta5.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4beta5.tar.gz ?download
MediaWiki MediaWiki 1.4 beta1
-
MediaWiki mediawiki-1.4beta5.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4beta5.tar.gz ?download
MediaWiki MediaWiki 1.4 beta4
-
MediaWiki mediawiki-1.4beta5.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4beta5.tar.gz ?download
References
MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilities
References:
References:
- MediaWiki Homepage (MediaWiki)
- Release Name: MediaWiki 1.4beta5 (MediaWiki)