CVE-2008-1318 |
|
发布时间 :2008-03-13 10:44:00 | ||
修订时间 :2011-04-18 00:00:00 | ||||
NMCO |
[原文]Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive “cross-site” information via the callback parameter in an API call for JavaScript Object Notation (JSON) formatted results.
[CNNVD]MediaWiki JavaScript Object Notation API信息泄露漏洞(CNNVD-200803-213)
MediaWiki存在未明漏洞。远程攻击者通过一个对JavaScript Object Notation (JSON)格式化的结果的应用程序接口(API)的请求中的callback参数来获得敏感的”跨站”信息。
–
CVSS (基础分值)
CVSS分值: | 5 | [中等(MEDIUM)] |
机密性影响: | PARTIAL | [很可能造成信息泄露] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | NONE | [对系统可用性无影响] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CWE (弱点类目)
CWE-200 | [信息暴露] |
–
CPE (受影响的平台与产品)
cpe:/a:mediawiki:mediawiki:1.11 | MediaWiki 1.11 |
cpe:/a:mediawiki:mediawiki:1.11.1 | MediaWiki 1.11.1 |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://www.securityfocus.com/bid/28070 (PATCH) BID 28070 |
http://secunia.com/advisories/29216 (VENDOR_ADVISORY) SECUNIA 29216 |
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-March/000070.html (PATCH) MLIST [MediaWiki-announce] 20080307 MediaWiki 1.11.2 released (security) |
http://xforce.iss.net/xforce/xfdb/40960 (UNKNOWN) XF mediawiki-jsoncallbacks-info-disclosure(40960) |
http://www.vupen.com/english/advisories/2008/0732/references (VENDOR_ADVISORY) VUPEN ADV-2008-0732 |
http://www.securitytracker.com/id?1019535 (UNKNOWN) SECTRACK 1019535 |
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_11_2/phase3/RELEASE-NOTES (UNKNOWN) CONFIRM http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_11_2/phase3/RELEASE-NOTES |
–
漏洞信息
MediaWiki JavaScript Object Notation API信息泄露漏洞 | |
中危 | 信息泄露 |
2008-03-13 00:00:00 | 2008-09-05 00:00:00 |
远程 | |
MediaWiki存在未明漏洞。远程攻击者通过一个对JavaScript Object Notation (JSON)格式化的结果的应用程序接口(API)的请求中的callback参数来获得敏感的”跨站”信息。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: MediaWiki MediaWiki 1.11 MediaWiki mediawiki-1.11.2.tar.gz http://download.wikimedia.org/mediawiki/1.11/mediawiki-1.11.2.tar.gz MediaWiki MediaWiki 1.11.1 MediaWiki mediawiki-1.11.2.tar.gz http://download.wikimedia.org/mediawiki/1.11/mediawiki-1.11.2.tar.gz |
–
漏洞信息
42588 |
|
MediaWiki JSON Callback Crafted API Request Information Disclosure | |
Remote / Network Access |
Information Disclosure, Input Manipulation |
Loss of Confidentiality | Upgrade |
Vendor Verified |
–
漏洞描述
–
时间线
2008-03-03 |
Unknow |
Unknow | 2008-03-03 |
–
解决方案
Upgrade to version 1.11.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. |
–
相关参考
|
–
漏洞作者
Unknown or Incomplete |