MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-12-19T17:00:00
Updated: 2024-08-07T11:04:44.334Z
Reserved: 2008-12-19T00:00:00
Link: CVE-2008-5687
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-12-19T17:30:03.360
Modified: 2024-11-21T00:54:38.913
Link: CVE-2008-5687
Redhat
No data.