Korean
<< Back
VID 21780
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description A version of MediaWiki 1.5 which is older than version 1.5.3 is detected as installed on the host. MediaWiki is a freely available editing program for Wikipedia, Wiktionary, and other software written in PHP. MediaWiki versions 1.5.x prior to 1.5.3 could allow a remote attacker to inject and execute arbitrary PHP code, caused by improper filtering of user-supplied input in an "eval()" call. A remote attacker can send a specially-crafted URL request to execute arbitrary PHP code and operating system commands on the target system.

* Note: This check solely relied on the version number of MediaWiki on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://secunia.com/advisories/17866/

* Platforms Affected:
The Wikimedia Foundation, Inc., MediaWiki versions 1.5.x prior to 1.5.3
Any operating system Any version
Recommendation Upgrade to the latest version of MediaWiki (1.5.3 or later), available from the MediaWiki Web page at http://www.mediawiki.org/wiki/Download#Stable
Related URL CVE-2005-4031 (CVE)
Related URL 15703 (SecurityFocus)
Related URL (ISS)