Vulnerability Name: | CCN-90807 | ||||||
Published: | 2014-01-28 | ||||||
Updated: | 2014-01-28 | ||||||
Summary: | MediaWiki could allow a remote attacker to execute arbitrary code on the system, caused by the improper handling of DjVu files. If the DjVu file type upload support is enabled, an attacker could exploit this vulnerability to execute arbitrary code on the system. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: MediaWiki Mailing List, Tue Jan 28 21:27:50 UTC 2014 MediaWiki Security Releases: 1.22.2, 1.21.5 and 1.19.11 Source: CCN Type: SA56695 MediaWiki Two Code Execution Vulnerabilities Source: CCN Type: MediaWiki Web site MediaWiki Source: XF Type: UNKNOWN mediawiki-djvu-code-exec(90807) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |