Vulnerability Name: | CVE-2011-4360 (CCN-71522) | ||||||||||||||||
Assigned: | 2011-11-28 | ||||||||||||||||
Published: | 2011-11-28 | ||||||||||||||||
Updated: | 2021-04-21 | ||||||||||||||||
Summary: | MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-4360 Source: CCN Type: MediaWiki Web page MediaWiki security release 1.17.1 Source: MLIST Type: Patch, Vendor Advisory [mediawiki-announce] 20111128 MediaWiki security release 1.17.1 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20111129 Re: CVE request: mediawiki before 1.17.1 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20111129 CVE request: mediawiki before 1.17.1 Source: CCN Type: SA47029 MediaWiki Private Page Title Disclosure Weakness Source: DEBIAN Type: Third Party Advisory DSA-2366 Source: DEBIAN Type: DSA-2366 mediawiki -- multiple vulnerabilities Source: CCN Type: MediaWiki Web Site MediaWiki Source: CCN Type: OSVDB ID: 77364 MediaWiki preliminaryChecks() Function curid Parameter Request Parsing Remote Private Page Title Disclosure Source: CCN Type: BID-50844 MediaWiki Multiple Information Disclosure Vulnerabilities Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=758171 Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://bugzilla.wikimedia.org/show_bug.cgi?id=32276 Source: XF Type: UNKNOWN mediawiki-index-information-disclosure(71522) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |