CVE-2008-5687
published 2008-12-19CVE-2008-5687: MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.96%
78.2th percentile
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.13.3-1 (bookworm) | mediawiki 1:1.13.3-1 (bookworm) |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.13.3-1 | 1:1.13.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.13.3-1 | 1:1.13.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.13.3-1 | 1:1.13.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.13.3-1 | 1:1.13.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjqg-xp72-5w5q: MediaWiki 1
ghsa_unreviewed·2022-05-17
CVE-2008-5687 [MEDIUM] GHSA-jjqg-xp72-5w5q: MediaWiki 1
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
OSV
CVE-2008-5687: MediaWiki 1
osv·2008-12-19·CVSS 5.0
CVE-2008-5687 [MEDIUM] CVE-2008-5687: MediaWiki 1
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
Debian
CVE-2008-5687: mediawiki - MediaWiki 1.11, and other versions before 1.13.3, does not properly protect agai...
vendor_debian·2008·CVSS 5.0
CVE-2008-5687 [MEDIUM] CVE-2008-5687: mediawiki - MediaWiki 1.11, and other versions before 1.13.3, does not properly protect agai...
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
Scope: local
bookworm: resolved (fixed in 1:1.13.3-1)
bullseye: resolved (fixed in 1:1.13.3-1)
forky: resolved (fixed in 1:1.13.3-1)
sid: resolved (fixed in 1:1.13.3-1)
trixie: resolved (fixed in 1:1.13.3-1)
No detection rules found.
Bugzilla
mediawiki: multiple XSS and CSRF issues (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688)
bugzilla·2008-12-16·CVSS 4.3
CVE-2008-5249 [MEDIUM] mediawiki: multiple XSS and CSRF issues (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688)
mediawiki: multiple XSS and CSRF issues (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688)
MediWiki upstream released new upstream versions -- 1.13.3, 1.12.1 and 1.6.11 -- with multiple security fixes:
* An XSS vulnerability affecting all MediaWiki installations between
1.13.0 and 1.13.2. [CVE-2008-5249]
* A local script injection vulnerability affecting Internet Explorer
clients for all MediaWiki installations with uploads enabled.
[CVE-2008-5250]
* A local script injection vulnerability affecting clients with SVG
scripting capability (such as Firefox 1.5+), for all MediaWiki
installations with SVG uploads enabled. [CVE-2008-5250]
* A CSRF vulnerability affecting the Special:Import feature, for all
MediaWiki installations since the feature was introduced in 1
Bugzilla
CVE-2008-2549 acroread: crash and possible code execution
bugzilla·2008-06-05·CVSS 4.3
CVE-2008-2549 [MEDIUM] CVE-2008-2549 acroread: crash and possible code execution
CVE-2008-2549 acroread: crash and possible code execution
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2549 to the following vulnerability:
Adobe Acrobat Reader 8.1.2 and earlier allows remote attackers to
cause a denial of service (application crash) and possibly execute
arbitrary code via a malformed PDF document, as demonstrated by
2008-HI2.pdf.
References:
http://www.milw0rm.com/exploits/5687
http://www.securityfocus.com/bid/29420
Discussion:
Created attachment 308415
Public PoC
http://www.milw0rm.com/exploits/5687
http://milw0rm.com/sploits/2008-HI2.pdf
---
Fixed upstream in 8.1.3:
http://www.adobe.com/support/security/bulletins/apsb08-19.html
---
This issue was addressed in:
Red Hat Enterprise Linux Extras:
http://rhn.redhat.com/errata/RHSA-2008-097
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.htmlhttp://secunia.com/advisories/33349https://exchange.xforce.ibmcloud.com/vulnerabilities/47678https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.htmlhttp://secunia.com/advisories/33349https://exchange.xforce.ibmcloud.com/vulnerabilities/47678https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html
2008-12-19
Published