CVE-2011-0537
N/A
N/A
Summary
Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Windows and possibly Novell Netware, allow remote attackers to include and execute arbitrary local PHP files via vectors related to a crafted language file and the Language::factory function.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.vupen.com/english/advisories/2011/0273
- http://osvdb.org/70799
- https://bugzilla.wikimedia.org/show_bug.cgi?id=27094
- http://www.openwall.com/lists/oss-security/2011/02/03/3
- http://download.wikimedia.org/mediawiki/1.16/mediawiki-1.16.2.patch.gz
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html
- http://www.openwall.com/lists/oss-security/2011/02/01/4
- http://osvdb.org/70798
References
- http://www.vupen.com/english/advisories/2011/0273
- http://osvdb.org/70799
- https://bugzilla.wikimedia.org/show_bug.cgi?id=27094
- http://www.openwall.com/lists/oss-security/2011/02/03/3
- http://download.wikimedia.org/mediawiki/1.16/mediawiki-1.16.2.patch.gz
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html
- http://www.openwall.com/lists/oss-security/2011/02/01/4
- http://osvdb.org/70798
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.