CVE-2007-0894
published 2007-02-12CVE-2007-0894: MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3)…
PriorityP48medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.97%
78.3th percentile
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.10 (bookworm) | mediawiki 1:1.10 (bookworm) |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pg5-q3hf-7698: MediaWiki before 1
ghsa_unreviewed·2022-05-01
CVE-2007-0894 [MEDIUM] GHSA-4pg5-q3hf-7698: MediaWiki before 1
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
OSV
CVE-2007-0894: MediaWiki before 1
osv·2007-02-12·CVSS 5.0
CVE-2007-0894 [MEDIUM] CVE-2007-0894: MediaWiki before 1
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Debian
CVE-2007-0894: mediawiki - MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information v...
vendor_debian·2007·CVSS 5.0
CVE-2007-0894 [MEDIUM] CVE-2007-0894: mediawiki - MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information v...
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Scope: local
bookworm: resolved (fixed in 1:1.10)
bullseye: resolved (fixed in 1:1.10)
forky: resolved (fixed in 1:1.10)
sid: resolved (fixed in 1:1.10)
trixie: resolved (fixed in 1:1.10)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
bugzilla·2007-05-29·CVSS 6.0
CVE-2007-2692 [MEDIUM] CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
Description of problem:
Functions declared as SECURITY INVOKER do not drop privileges upon
return and thus make it possible for an authenticated user calling
then can gain certain privileges.
Version-Release number of selected component (if applicable):
MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18
Discussion:
This issue was addressed in:
Red Hat Application Stack:
http://rhn.redhat.com/errata/RHSA-2007-0894.html
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0364.html
---
Reporter changed to [email protected] by request of Jay Turner.
Bugzilla
CVE-2007-0894: mediawiki full path disclosure
bugzilla·2007-02-14·CVSS 5.0
CVE-2007-0894 [MEDIUM] CVE-2007-0894: mediawiki full path disclosure
CVE-2007-0894: mediawiki full path disclosure
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0894
"MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information
via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3)
MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the
installation path in the resulting error message."
1.8.3 (current FE6) in the CVE entry is not listed as vulnerable, don't know if
the omission is intentional. And whether installation path disclosure is an
issue with Fedora packages can also be debated, reporting here just in case
there's more to it.
Discussion:
Thanks for the heads-up (1.8.3 should be vulerable as well, it was probably
forgotten in the list of vulnerable versions).
Indeed for the package we aren't losin
http://bugzilla.wikimedia.org/show_bug.cgi?id=8819http://osvdb.org/33706http://osvdb.org/33707http://osvdb.org/33708http://osvdb.org/33709http://svn.wikimedia.org/viewvc/mediawiki?view=rev&revision=19681http://www.securityfocus.com/archive/1/459793/100/0/threadedhttp://zone14.free.fr/advisories/7/https://exchange.xforce.ibmcloud.com/vulnerabilities/32440http://bugzilla.wikimedia.org/show_bug.cgi?id=8819http://osvdb.org/33706http://osvdb.org/33707http://osvdb.org/33708http://osvdb.org/33709http://svn.wikimedia.org/viewvc/mediawiki?view=rev&revision=19681http://www.securityfocus.com/archive/1/459793/100/0/threadedhttp://zone14.free.fr/advisories/7/https://exchange.xforce.ibmcloud.com/vulnerabilities/32440
2007-02-12
Published