MediaWiki 1.16.4 Multiple Remote Vulnerabilities
BID:47722
Info
MediaWiki 1.16.4 Multiple Remote Vulnerabilities
| Bugtraq ID: | 47722 |
| Class: | Unknown |
| CVE: |
CVE-2011-1765 CVE-2011-1766 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2011 12:00AM |
| Updated: | May 07 2015 05:15PM |
| Credit: | Masato Kinugawa and Liangent |
| Vulnerable: |
MediaWiki MediaWiki 1.16.4 Gentoo Linux |
| Not Vulnerable: |
MediaWiki MediaWiki 1.16.5 |
Discussion
MediaWiki 1.16.4 Multiple Remote Vulnerabilities
MediaWiki is prone to multiple remote vulnerabilities, including:
1. A cross-site scripting vulnerability.
2. An authentication-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based authentication credentials, and gain unauthorized access to the affected application.
MediaWiki 1.16.4 is vulnerable; other versions may also be affected.
MediaWiki is prone to multiple remote vulnerabilities, including:
1. A cross-site scripting vulnerability.
2. An authentication-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based authentication credentials, and gain unauthorized access to the affected application.
MediaWiki 1.16.4 is vulnerable; other versions may also be affected.
Exploit / POC
MediaWiki 1.16.4 Multiple Remote Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
MediaWiki 1.16.4 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
MediaWiki 1.16.4 Multiple Remote Vulnerabilities
References:
References:
- Bug 28639 - Trivial account takeover using forged cookies possible (MediaWiki)
- MediaWiki Homepage (MediaWiki)