Lucene search

K
nvd[email protected]NVD:CVE-2010-1648
HistoryJun 08, 2010 - 12:30 a.m.

CVE-2010-1648

2010-06-0800:30:01
CWE-352
web.nvd.nist.gov
6

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.7%

Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.

Affected configurations

Nvd
Node
mediawikimediawikiMatch1.15.0
OR
mediawikimediawikiMatch1.15.0rc1
OR
mediawikimediawikiMatch1.15.1
OR
mediawikimediawikiMatch1.15.2
OR
mediawikimediawikiMatch1.15.3
OR
mediawikimediawikiMatch1.16.0
OR
mediawikimediawikiMatch1.16.0beta1
OR
mediawikimediawikiMatch1.16.0beta2
VendorProductVersionCPE
mediawikimediawiki1.15.0cpe:2.3:a:mediawiki:mediawiki:1.15.0:*:*:*:*:*:*:*
mediawikimediawiki1.15.0cpe:2.3:a:mediawiki:mediawiki:1.15.0:rc1:*:*:*:*:*:*
mediawikimediawiki1.15.1cpe:2.3:a:mediawiki:mediawiki:1.15.1:*:*:*:*:*:*:*
mediawikimediawiki1.15.2cpe:2.3:a:mediawiki:mediawiki:1.15.2:*:*:*:*:*:*:*
mediawikimediawiki1.15.3cpe:2.3:a:mediawiki:mediawiki:1.15.3:*:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:*:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta1:*:*:*:*:*:*
mediawikimediawiki1.16.0cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta2:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.7%