CVE-2012-1580
Gentoo Linux Security Advisory 201206-09
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Special:Upload en MediaWiki v1.17.x antes de v1.17.3 y v1.18.x antes de v1.18.2, permite a atacantes remotos secuestrar la autenticación de las víctimas no especificadas para las solicitudes que suben archivos.
Multiple vulnerabilities have been found in MediaWiki, the worst of which leading to remote execution of arbitrary code. Versions less than 1.18.2 are affected.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-03-12 CVE Reserved
- 2012-06-22 CVE Published
- 2024-08-06 CVE Updated
- 2025-06-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/80364 | Vdb Entry | |
http://www.openwall.com/lists/oss-security/2012/03/22/9 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2012/03/24/1 | Mailing List |
|
http://www.securityfocus.com/bid/52689 | Vdb Entry | |
https://bugzilla.wikimedia.org/show_bug.cgi?id=35317 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74286 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.html | 2017-08-29 | |
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.html | 2017-08-29 | |
http://secunia.com/advisories/48504 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17" | beta_1 |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17.0" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17.0" | rc1 |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17.1 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17.1" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.17.2 Search vendor "Mediawiki" for product "Mediawiki" and version "1.17.2" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.18 Search vendor "Mediawiki" for product "Mediawiki" and version "1.18" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.18 Search vendor "Mediawiki" for product "Mediawiki" and version "1.18" | beta_1 |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.18.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.18.0" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.18.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.18.0" | rc1 |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.18.1 Search vendor "Mediawiki" for product "Mediawiki" and version "1.18.1" | - |
Affected
|