5
CVSSv2

CVE-2013-4301

Published: 27/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x prior to 1.19.8, 1.20.x prior to 1.20.7, and 1.21.x prior to 1.21.2 allows remote malicious users to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter to w/load.php, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.20.1

mediawiki mediawiki 1.20.2

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.20.5

mediawiki mediawiki 1.20.6

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.20.3

mediawiki mediawiki 1.20.4

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.21

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.20

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.1