Vulnerability Name: | CVE-2013-2114 (CCN-84527) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2013-05-24 | ||||||||||||||||||||||||||||||||||||
Published: | 2013-05-24 | ||||||||||||||||||||||||||||||||||||
Updated: | 2013-11-21 | ||||||||||||||||||||||||||||||||||||
Summary: | Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. CWE-434: Unrestricted Upload of File with Dangerous Type per http://cwe.mitre.org/data/definitions/434.html | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-2114 Source: CCN Type: MediaWiki Web Site MediaWiki Source: MLIST Type: Patch [MediaWiki-announce] 20130521 MediaWiki Security Release: 1.20.6 and 1.19.7 Source: SECUNIA Type: Vendor Advisory 55433 Source: GENTOO Type: UNKNOWN GLSA-201310-21 Source: MLIST Type: UNKNOWN [oss-security] 20130524 Re: CVE request: MediaWiki chunked uploads vulnerability Source: CCN Type: BID-60077 MediaWiki Arbitrary File Upload Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 967062 CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 Source: CCN Type: Bugzilla Bug 48306 Chunked uploads allow arbitrary data to be dropped on the server Source: CONFIRM Type: Patch https://bugzilla.wikimedia.org/show_bug.cgi?id=48306 Source: XF Type: UNKNOWN mediawiki-cve20132114-apiupload-file-upload(84527) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2114 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |