MediaWiki是美国维基媒体(Wikimedia)基金会和MediaWiki志愿者共同开发维护的一套自由免费的基于网络的Wiki引擎,它可用于部署内部的知识管理和内容管理系统。 Mediawiki 1.28.1之前版本、1.27.2之前版本和1.23.16之前版本中存在安全漏洞。攻击者可利用该漏洞将用户重定向外部网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-0361 | api.log contains passwords in plaintext | |
| CVE-2017-0362 | "Mark all pages visited" on the watchlist does not require a CSRF token | |
| CVE-2017-0364 | Special:Search allows redirects to any interwiki link | |
| CVE-2017-0365 | XSS in SearchHighlighter::highlightText() [requires non-default config] | |
| CVE-2017-0366 | SVG filter evasion using default attribute values in DTD declaration | |
| CVE-2017-0367 | Having LocalisationCache directory default to system tmp directory is insecure | |
| CVE-2017-0368 | Make rawHTML mode not apply to system messages | |
| CVE-2017-0369 | Sysops can undelete pages, although the page is protected against it | |
| CVE-2017-0370 | Spam blacklist ineffective on encoded URLs inside file inclusion syntax's link parameter | |
| CVE-2017-0372 | Parameters injection in SyntaxHighlight results in multiple vulnerabilities |
No comments yet