| VID |
21780 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
A version of MediaWiki 1.5 which is older than version 1.5.3 is detected as installed on the host. MediaWiki is a freely available editing program for Wikipedia, Wiktionary, and other software written in PHP. MediaWiki versions 1.5.x prior to 1.5.3 could allow a remote attacker to inject and execute arbitrary PHP code, caused by improper filtering of user-supplied input in an "eval()" call. A remote attacker can send a specially-crafted URL request to execute arbitrary PHP code and operating system commands on the target system.
* Note: This check solely relied on the version number of MediaWiki on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/17866/
* Platforms Affected: The Wikimedia Foundation, Inc., MediaWiki versions 1.5.x prior to 1.5.3 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of MediaWiki (1.5.3 or later), available from the MediaWiki Web page at http://www.mediawiki.org/wiki/Download#Stable |
| Related URL |
CVE-2005-4031 (CVE) |
| Related URL |
15703 (SecurityFocus) |
| Related URL |
(ISS) |
|