CVE-2014-1610
MediaWiki - 'Thumb.php' Remote Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
MediaWiki 1.22.x en versiones anteriores a 1.22.2, 1.21.x en versiones anteriores a 1.21.5 y 1.19.x en versiones anteriores a 1.19.11, cuando el soporte a la carga de archivos DjVu o PDF está habilitado, permite a atacantes remotos ejecutar comandos arbitrarios a través de metacaracteres shell en (1) el parámetro page en includes/media/DjVu.php; (2) el parámetro w (también conocido como campo width) en thumb.php, lo que no se maneja correctamente por includes/media/PdfHandler_body.php; y posiblemente vectores no especificados en (3) includes/media/Bitmap.php e (4) includes/media/ImageHandler.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-19 CVE Reserved
- 2014-01-30 CVE Published
- 2014-02-01 First Exploit
- 2024-08-06 CVE Updated
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (21)
URL | Tag | Source |
---|---|---|
http://osvdb.org/102630 | Vdb Entry | |
http://secunia.com/advisories/57472 | Third Party Advisory | |
http://www.checkpoint.com/defense/advisories/public/2014/cpai-26-jan.html | X_refsource_misc | |
http://www.checkpoint.com/threatcloud-central/articles/2014-01-28-tc-researchers-discover.html | X_refsource_misc | |
http://www.osvdb.org/102631 | Vdb Entry | |
http://www.securityfocus.com/bid/65223 | Vdb Entry | |
http://www.securitytracker.com/id/1029707 | Vdb Entry | |
https://bugzilla.wikimedia.org/attachment.cgi?id=14361&action=diff | X_refsource_misc | |
https://bugzilla.wikimedia.org/attachment.cgi?id=14384&action=diff | X_refsource_misc | |
https://bugzilla.wikimedia.org/show_bug.cgi?id=60339 | X_refsource_confirm | |
https://gerrit.wikimedia.org/r/#/c/110069/2/includes/media/Bitmap.php | X_refsource_misc | |
https://gerrit.wikimedia.org/r/#/c/110215 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31767 | 2014-02-19 | |
https://www.exploit-db.com/exploits/31329 | 2014-02-01 | |
http://www.exploit-db.com/exploits/31329 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.0" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.1 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.1" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.2 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.2" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.3 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.3" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.4 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.4" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.5 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.5" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.6 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.6" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.7 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.7" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.8 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.8" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.9 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.9" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.19.10 Search vendor "Mediawiki" for product "Mediawiki" and version "1.19.10" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.21.1 Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.1" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.21.2 Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.2" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.21.3 Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.3" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.21.4 Search vendor "Mediawiki" for product "Mediawiki" and version "1.21.4" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.22.0 Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.0" | - |
Affected
| ||||||
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | 1.22.1 Search vendor "Mediawiki" for product "Mediawiki" and version "1.22.1" | - |
Affected
|