MediaWiki Multiple Remote Code Execution Vulnerabilities
BID:65223
Info
MediaWiki Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 65223 |
| Class: | Unknown |
| CVE: |
CVE-2014-1610 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2014 12:00AM |
| Updated: | Apr 13 2015 09:40PM |
| Credit: | Netanel Rubin, Reported by the vendor. |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
MediaWiki Multiple Remote Code Execution Vulnerabilities
MediaWiki is prone to multiple remote code execution vulnerabilities.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Versions prior to 1.22.2, 1.21.5, or 1.19.11 are vulnerable.
MediaWiki is prone to multiple remote code execution vulnerabilities.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Versions prior to 1.22.2, 1.21.5, or 1.19.11 are vulnerable.
Exploit / POC
MediaWiki Multiple Remote Code Execution Vulnerabilities
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.