Show filters
373 Total Results
Displaying 191-200 of 373
Sort by:
Attacker Value
Unknown
CVE-2019-12473
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12472
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
CVE-2019-12466
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 allows CSRF.
0
Attacker Value
Unknown
CVE-2019-12468
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
0
Attacker Value
Unknown
CVE-2019-12467
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown
Information disclosure in Special:Redirect/logid
Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
0
Attacker Value
Unknown
$wgRateLimits entry for 'user' overrides 'newbie'
Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
0
Attacker Value
Unknown
Tarball was missing .htaccess files
Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
0
Attacker Value
Unknown
BotPasswords can bypass CentralAuth's account lock
Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
0
Attacker Value
Unknown
CVE-2014-1686
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
0