Lucene search

K
cve[email protected]CVE-2014-1610
HistoryJan 30, 2014 - 11:55 p.m.

CVE-2014-1610

2014-01-3023:55:02
CWE-20
web.nvd.nist.gov
124
cve-2014-1610
mediawiki
remote code execution
shell metacharacters
djvu
pdf
nvd
security vulnerability

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.9

Confidence

High

EPSS

0.083

Percentile

94.4%

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.

Affected configurations

NVD
Node
mediawikimediawikiMatch1.19.0
OR
mediawikimediawikiMatch1.19.1
OR
mediawikimediawikiMatch1.19.2
OR
mediawikimediawikiMatch1.19.3
OR
mediawikimediawikiMatch1.19.4
OR
mediawikimediawikiMatch1.19.5
OR
mediawikimediawikiMatch1.19.6
OR
mediawikimediawikiMatch1.19.7
OR
mediawikimediawikiMatch1.19.8
OR
mediawikimediawikiMatch1.19.9
OR
mediawikimediawikiMatch1.19.10
OR
mediawikimediawikiMatch1.21.1
OR
mediawikimediawikiMatch1.21.2
OR
mediawikimediawikiMatch1.21.3
OR
mediawikimediawikiMatch1.21.4
OR
mediawikimediawikiMatch1.22.0
OR
mediawikimediawikiMatch1.22.1
VendorProductVersionCPE
mediawikimediawiki1.19.1cpe:/a:mediawiki:mediawiki:1.19.1:::
mediawikimediawiki1.19.5cpe:/a:mediawiki:mediawiki:1.19.5:::
mediawikimediawiki1.19.7cpe:/a:mediawiki:mediawiki:1.19.7:::
mediawikimediawiki1.19.8cpe:/a:mediawiki:mediawiki:1.19.8:::
mediawikimediawiki1.21.2cpe:/a:mediawiki:mediawiki:1.21.2:::
mediawikimediawiki1.21.3cpe:/a:mediawiki:mediawiki:1.21.3:::
mediawikimediawiki1.19.3cpe:/a:mediawiki:mediawiki:1.19.3:::
mediawikimediawiki1.19.6cpe:/a:mediawiki:mediawiki:1.19.6:::
mediawikimediawiki1.21.1cpe:/a:mediawiki:mediawiki:1.21.1:::
mediawikimediawiki1.21.4cpe:/a:mediawiki:mediawiki:1.21.4:::
Rows per page:
1-10 of 171

References

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.9

Confidence

High

EPSS

0.083

Percentile

94.4%