6
CVSSv2

CVE-2014-1610

Published: 30/01/2014 Updated: 25/05/2016
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 610
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

MediaWiki 1.22.x prior to 1.22.2, 1.21.x prior to 1.21.5, and 1.19.x prior to 1.19.11, when DjVu or PDF file upload support is enabled, allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.19.2

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.21.4

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.21.2

mediawiki mediawiki 1.21.3

mediawiki mediawiki 1.19.10

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.8

mediawiki mediawiki 1.22.1

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.19.9

mediawiki mediawiki 1.22.0

Vendor Advisories

Debian Bug report logs - #742857 mediawiki: login CSRF in Special:ChangePassword Package: mediawiki; Maintainer for mediawiki is Kunal Mehta <legoktm@debianorg>; Source for mediawiki is src:mediawiki (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Fri, 28 Mar 2014 07:03:01 UTC Severity: importan ...
Several vulnerabilities were discovered in MediaWiki, a wiki engine The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-2031 Cross-site scripting attack via valid UTF-7 encoded sequences in a SVG file CVE-2013-4567 & CVE-2013-4568 Kevin Israel (Wikipedia user PleaseStand) reported two wa ...

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 #################################################################### # # MediaWiki <= 1221 PdfHandler Remote Code Execution Exploit (CVE-2014-1610) # Reported by Netanel Rubin - Check Point’s Vulnerability Research Group (Jan 19, 2014) # Fixed in 1222, 1215 and 11911 (Jan 30, 2014) # Affec ...
## # This module requires Metasploit: http//metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient def initialize(info = {}) super(update_info(info, 'Name' => 'Me ...
MediaWiki 122x before 1222, 121x before 1215 and 119x before 11911, when DjVu or PDF file upload support is enabled, allows remote unauthenticated users to execute arbitrary commands via shell metacharacters If no target file is specified this module will attempt to log in with the provided credentials to upload a file (DjVu) to use f ...
MediaWiki versions 1221 and below PdfHandler remote code execution exploit ...