| VID |
21684 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
A beta version of MediaWiki which is older than version 1.4beta5 is detected as installed on the host. MediaWiki is a freely available editing program for Wikipedia, Wiktionary, and other software written in PHP. MediaWiki versions 1.4beta though 1.4beta4 could allow a remote attacker to execute arbitrary PHP code on the system, caused by improper validation of user-supplied input in the 'setup.php' and the 'SpecialPreferences.php' scripts. A remote attacker can send a specially-crafted URL request to execute arbitrary PHP code and operating system commands on the target system.
* Note: This check solely relied on the version number of MediaWiki on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://www.securitytracker.com/alerts/2005/Jan/1012923.html
* Platforms Affected: The Wikimedia Foundation, Inc., MediaWiki versions 1.4beta though 1.4beta4 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of MediaWiki (1.4beta5 or later), available from the MediaWiki Web page at http://wikipedia.sourceforge.net/ |
| Related URL |
(CVE) |
| Related URL |
12305 (SecurityFocus) |
| Related URL |
18949 (ISS) |
|