5
CVSSv2

CVE-2015-8005

Published: 09/11/2015 Updated: 10/11/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote malicious users to obtain the installation path by reading the metadata of a PNG thumbnail file.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki

mediawiki mediawiki 1.25.1

mediawiki mediawiki 1.25.2

mediawiki mediawiki 1.24.1

mediawiki mediawiki 1.24.3

mediawiki mediawiki 1.24.0

mediawiki mediawiki 1.24.2

mediawiki mediawiki 1.25.0