oval:org.mitre.oval:def:15086
Definition Id: oval:org.mitre.oval:def:15086 | |||
Oval ID: | oval:org.mitre.oval:def:15086 | ||
Title: | DSA-2366-1 mediawiki -- multiple | ||
Description: | Several problems have been discovered in mediawiki, a website engine for collaborative work. CVE-2011-1578 CVE-2011-1587 Masato Kinugawa discovered a cross-site scripting issue, which affects Internet Explorer clients only, and only version 6 and earlier. Web server configuration changes are required to fix this issue. Upgrading MediaWiki will only be sufficient for people who use Apache with AllowOverride enabled. This is an XSS issue for Internet Explorer clients, and a privacy loss issue for other clients since it allows the embedding of arbitrary remote images. CVE-2011-1580 MediaWiki developer Happy-Melon discovered that the transwiki import feature neglected to perform access control checks on form submission. The transwiki import feature is disabled by default. If it is enabled, it allows wiki pages to be copied from a remote wiki listed in $wgImportSources. The issue means that any user can trigger such an import to occur. CVE-2011-4360 Alexandre Emsenhuber discovered an issue where page titles on private wikis could be exposed bypassing different page ids to index.php. In the case of the user not having correct permissions, they will now be redirected to Special:BadTitle. CVE-2011-4361 Tim Starling discovered that action=ajax requests were dispatched to the relevant function without any read permission checks being done. This could have led to data leakage on private wikis. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2366-1 CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 CVE-2011-4360 CVE-2011-4361 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | mediawiki |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6513 | |||
Oval ID: | oval:org.mitre.oval:def:6513 | ||
Title: | Debian GNU/Linux 5.0 is installed | ||
Description: | Debian GNU/Linux 5.0 (lenny) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux:5.0 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15086 |
Definition Id: oval:org.mitre.oval:def:12959 | |||
Oval ID: | oval:org.mitre.oval:def:12959 | ||
Title: | Debian 6.0 is installed | ||
Description: | Debian 6.0 (squeeze) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian:6.0 | Version: | 6 |
Platform(s): | Debian 6.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15086 |
Definition Id: oval:org.mitre.oval:def:24698 | |||
Oval ID: | oval:org.mitre.oval:def:24698 | ||
Title: | Debian GNU/kFreeBSD is installed | ||
Description: | Debian GNU/kFreeBSD is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/kfreebsd | Version: | 3 |
Platform(s): | Debian GNU/kFreeBSD | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15086 |
Definition Id: oval:org.mitre.oval:def:24894 | |||
Oval ID: | oval:org.mitre.oval:def:24894 | ||
Title: | Debian GNU/Linux is installed | ||
Description: | Debian GNU/Linux is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux | Version: | 3 |
Platform(s): | Debian GNU/Linux | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15086 |