Korean
<< Back
VID 21684
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description A beta version of MediaWiki which is older than version 1.4beta5 is detected as installed on the host. MediaWiki is a freely available editing program for Wikipedia, Wiktionary, and other software written in PHP. MediaWiki versions 1.4beta though 1.4beta4 could allow a remote attacker to execute arbitrary PHP code on the system, caused by improper validation of user-supplied input in the 'setup.php' and the 'SpecialPreferences.php' scripts. A remote attacker can send a specially-crafted URL request to execute arbitrary PHP code and operating system commands on the target system.

* Note: This check solely relied on the version number of MediaWiki on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.securitytracker.com/alerts/2005/Jan/1012923.html

* Platforms Affected:
The Wikimedia Foundation, Inc., MediaWiki versions 1.4beta though 1.4beta4
Any operating system Any version
Recommendation Upgrade to the latest version of MediaWiki (1.4beta5 or later), available from the MediaWiki Web page at http://wikipedia.sourceforge.net/
Related URL (CVE)
Related URL 12305 (SecurityFocus)
Related URL 18949 (ISS)