Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.806625
Kategorie:Web application abuses
Titel:MediaWiki Multiple Vulnerabilities - Nov15 (Windows)
Zusammenfassung:This host is installed with MediaWiki; and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is installed with MediaWiki
and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- the chunked upload API (ApiUpload) which does not restrict the uploaded
data to the claimed file size.

- an error in the application which does not throttle file uploads.

- improper restrict access to revisions.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to conduct denial of service attack, gain privileged access and
have some other unspecified impact.

Affected Software/OS:
MediaWiki before 1.23.11, 1.24.x before
1.24.4, and 1.25.x before 1.25.3 on Windows

Solution:
Upgrade to version 1.23.11 or 1.24.4
or 1.25.3 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:C

Querverweis: BugTraq ID: 77378
BugTraq ID: 77375
BugTraq ID: 77374
BugTraq ID: 77372
Common Vulnerability Exposure (CVE) ID: CVE-2015-8005
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html
http://www.securitytracker.com/id/1034028
Common Vulnerability Exposure (CVE) ID: CVE-2015-8004
Common Vulnerability Exposure (CVE) ID: CVE-2015-8003
Common Vulnerability Exposure (CVE) ID: CVE-2015-8002
Common Vulnerability Exposure (CVE) ID: CVE-2015-8001
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.