| Vulnerability Name: | CVE-2011-4360 (CCN-71522) | ||||||||||||||||
| Assigned: | 2011-11-28 | ||||||||||||||||
| Published: | 2011-11-28 | ||||||||||||||||
| Updated: | 2021-04-21 | ||||||||||||||||
| Summary: | MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter. | ||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2011-4360 Source: CCN Type: MediaWiki Web page MediaWiki security release 1.17.1 Source: MLIST Type: Patch, Vendor Advisory [mediawiki-announce] 20111128 MediaWiki security release 1.17.1 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20111129 Re: CVE request: mediawiki before 1.17.1 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20111129 CVE request: mediawiki before 1.17.1 Source: CCN Type: SA47029 MediaWiki Private Page Title Disclosure Weakness Source: DEBIAN Type: Third Party Advisory DSA-2366 Source: DEBIAN Type: DSA-2366 mediawiki -- multiple vulnerabilities Source: CCN Type: MediaWiki Web Site MediaWiki Source: CCN Type: OSVDB ID: 77364 MediaWiki preliminaryChecks() Function curid Parameter Request Parsing Remote Private Page Title Disclosure Source: CCN Type: BID-50844 MediaWiki Multiple Information Disclosure Vulnerabilities Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=758171 Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://bugzilla.wikimedia.org/show_bug.cgi?id=32276 Source: XF Type: UNKNOWN mediawiki-index-information-disclosure(71522) | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||