6.8
CVSSv2

CVE-2013-2114

Published: 18/11/2013 Updated: 21/11/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 up to and including 1.19.6 and 1.20.x prior to 1.20.6 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.20.5

mediawiki mediawiki 1.19

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.20.2

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.4