Vulnerability Name: | CVE-2008-5687 (CCN-47678) | ||||||||
Assigned: | 2008-12-15 | ||||||||
Published: | 2008-12-15 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5687 Source: CCN Type: MediaWiki-announce Mailing List, Mon Dec 15 11:09:28 UTC 2008 MediaWiki 1.13.3, 1.12.2, 1.6.11 security update Source: MLIST Type: UNKNOWN [mediawiki-announce] 20081215 MediaWiki 1.13.3, 1.12.2, 1.6.11 security update Source: SECUNIA Type: Vendor Advisory 33349 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: OSVDB ID: 51114 MediaWiki images/deleted/ Direct Request Remote Information Disclosure Source: XF Type: UNKNOWN mediawiki-images-info-disclosure(47678) Source: XF Type: UNKNOWN mediawiki-images-info-disclosure(47678) Source: FEDORA Type: UNKNOWN FEDORA-2008-11688 Source: FEDORA Type: UNKNOWN FEDORA-2008-11802 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |