Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.704036
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 4036-1 (mediawiki - security update)
Zusammenfassung:Multiple security vulnerabilities have been discovered in MediaWiki, a;website engine for collaborative work:;;CVE-2017-8808;Cross-site-scripting with non-standard URL escaping and;$wgShowExceptionDetails disabled.;;CVE-2017-8809;Reflected file download in API.;;CVE-2017-8810;On private wikis the login form didn't distinguish between;login failure due to bad username and bad password.;;CVE-2017-8811;It was possible to mangle HTML via raw message parameter;expansion.;;CVE-2017-8812;id attributes in headlines allowed raw '>'.;;CVE-2017-8814;Language converter could be tricked into replacing text inside tags.;;CVE-2017-8815;Unsafe attribute injection via glossary rules in language converter.
Beschreibung:Summary:
Multiple security vulnerabilities have been discovered in MediaWiki, a
website engine for collaborative work:

CVE-2017-8808
Cross-site-scripting with non-standard URL escaping and
$wgShowExceptionDetails disabled.

CVE-2017-8809
Reflected file download in API.

CVE-2017-8810
On private wikis the login form didn't distinguish between
login failure due to bad username and bad password.

CVE-2017-8811
It was possible to mangle HTML via raw message parameter
expansion.

CVE-2017-8812
id attributes in headlines allowed raw '>'.

CVE-2017-8814
Language converter could be tricked into replacing text inside tags.

CVE-2017-8815
Unsafe attribute injection via glossary rules in language converter.

Affected Software/OS:
mediawiki on Debian Linux

Solution:
For the stable distribution (stretch), these problems have been fixed in
version 1:1.27.4-1~
deb9u1.

We recommend that you upgrade your mediawiki packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-8808
Debian Security Information: DSA-4036 (Google Search)
https://www.debian.org/security/2017/dsa-4036
http://www.securitytracker.com/id/1039812
Common Vulnerability Exposure (CVE) ID: CVE-2017-8809
Common Vulnerability Exposure (CVE) ID: CVE-2017-8810
Common Vulnerability Exposure (CVE) ID: CVE-2017-8811
Common Vulnerability Exposure (CVE) ID: CVE-2017-8812
Common Vulnerability Exposure (CVE) ID: CVE-2017-8814
Common Vulnerability Exposure (CVE) ID: CVE-2017-8815
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.