CVE-2008-5688 — Sensitive Information Exposure in Mediawiki
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateMay 17
Description
MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which might allow remote attackers to obtain sensitive information via unspecified requests that trigger an uncaught exception.
CVSS vector
AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2008-5688: mediawiki - MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetai...↗2008
💬Community
1Bugzilla▶
mediawiki: multiple XSS and CSRF issues (CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688)↗2008-12-16