Executive Summary

Informations
NameCVE-2008-5252First vendor Publication2008-12-19
VendorCveLast vendor Modification2009-10-14

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:P)
Cvss Base Score5.8Attack RangeNetwork
Cvss Impact Score4.9Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5252

CWE : Common Weakness Enumeration

idName
CWE-352Cross-Site Request Forgery (CSRF)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application54

Open Source Vulnerability Database (OSVDB)

idDescription
50955MediaWiki Special:Import Feature Unspecified CSRF

Internal Sources (Detail)

SourceUrl
DEBIANhttp://www.debian.org/security/2009/dsa-1901
FEDORAhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg0125...
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg0130...
MLISThttp://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080....
SECUNIAhttp://secunia.com/advisories/33133
http://secunia.com/advisories/33349
SUSEhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-11 00:31:21
  • Multiple Updates