|
257591
|
6.5 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-0369
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257592
|
5.3 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
|
CWE-20
Improper Input Validation
|
CVE-2017-0368
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257593
|
8.8 |
HIGH
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-0367
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257594
|
5.4 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
|
CWE-20
Improper Input Validation
|
CVE-2017-0366
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257595
|
4.7 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
|
CWE-79
Cross-site Scripting
|
CVE-2017-0365
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257596
|
6.1 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
|
CWE-601
Open Redirect
|
CVE-2017-0364
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257597
|
6.1 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
|
CWE-601
Open Redirect
|
CVE-2017-0363
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257598
|
8.8 |
HIGH
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
|
CWE-352
Origin Validation Error
|
CVE-2017-0362
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257599
|
7.8 |
HIGH
Local
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
|
CWE-200
Information Exposure
|
CVE-2017-0361
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257600
|
9.8 |
CRITICAL
Network
|
reproducible_builds debian
|
diffoscope debian_linux
|
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
|
NVD-CWE-noinfo
|
CVE-2017-0359
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|