Lucene search

K
cveRedhatCVE-2010-1648
HistoryJun 08, 2010 - 12:30 a.m.

CVE-2010-1648

2010-06-0800:30:01
CWE-352
redhat
web.nvd.nist.gov
36
cve-2010-1648
cross-site request forgery
csrf vulnerability
mediawiki
authentication hijack
remote attackers
special:userlogin form

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.7%

Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.

Affected configurations

Nvd
Node
mediawikimediawikiMatch1.15.0
OR
mediawikimediawikiMatch1.15.0rc1
OR
mediawikimediawikiMatch1.15.1
OR
mediawikimediawikiMatch1.15.2
OR
mediawikimediawikiMatch1.15.3
OR
mediawikimediawikiMatch1.16.0
OR
mediawikimediawikiMatch1.16.0beta1
OR
mediawikimediawikiMatch1.16.0beta2
VendorProductVersionCPE
mediawikimediawiki1.15.0cpe:2.3:a:mediawiki:mediawiki:1.15.0:*:*:*:*:*:*:*
mediawikimediawiki1.15.0cpe:2.3:a:mediawiki:mediawiki:1.15.0:rc1:*:*:*:*:*:*
mediawikimediawiki1.15.1cpe:2.3:a:mediawiki:mediawiki:1.15.1:*:*:*:*:*:*:*
mediawikimediawiki1.15.2cpe:2.3:a:mediawiki:mediawiki:1.15.2:*:*:*:*:*:*:*
mediawikimediawiki1.15.3cpe:2.3:a:mediawiki:mediawiki:1.15.3:*:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:*:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta1:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta2:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.7%