VID |
21780 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
A version of MediaWiki 1.5 which is older than version 1.5.3 is detected as installed on the host. MediaWiki is a freely available editing program for Wikipedia, Wiktionary, and other software written in PHP. MediaWiki versions 1.5.x prior to 1.5.3 could allow a remote attacker to inject and execute arbitrary PHP code, caused by improper filtering of user-supplied input in an "eval()" call. A remote attacker can send a specially-crafted URL request to execute arbitrary PHP code and operating system commands on the target system.
* Note: This check solely relied on the version number of MediaWiki on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/17866/
* Platforms Affected: The Wikimedia Foundation, Inc., MediaWiki versions 1.5.x prior to 1.5.3 Any operating system Any version |
Recommendation |
Upgrade to the latest version of MediaWiki (1.5.3 or later), available from the MediaWiki Web page at http://www.mediawiki.org/wiki/Download#Stable |
Related URL |
CVE-2005-4031 (CVE) |
Related URL |
15703 (SecurityFocus) |
Related URL |
(ISS) |
|