ALT-PU-2017-2786-1
Closed vulnerabilities
Modified: 2021-03-23
BDU:2018-00062
Уязвимость сценария api.php программного средства для реализации гипертекстовой среды MediaWiki, позволяющая нарушителю выполнить произвольный код
Modified: 2025-04-20
CVE-2017-8808
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8809
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8810
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8811
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8812
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8814
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
Modified: 2025-04-20
CVE-2017-8815
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036
- http://www.securitytracker.com/id/1039812
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-November/000216.html
- https://www.debian.org/security/2017/dsa-4036