CVE-2008-5687

MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.11:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.11:rc1:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.11.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.11.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:54

Type Values Removed Values Added
References () http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html - () http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html -
References () http://secunia.com/advisories/33349 - Vendor Advisory () http://secunia.com/advisories/33349 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47678 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47678 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html - () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html - () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html -

Information

Published : 2008-12-19 17:30

Updated : 2024-11-21 00:54


NVD link : CVE-2008-5687

Mitre link : CVE-2008-5687

CVE.ORG link : CVE-2008-5687


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-264

Permissions, Privileges, and Access Controls