CVE Vulnerabilities

CVE-2005-4031

Published: Dec 06, 2005 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the user language option, which is used as part of a dynamic class name that is processed using the eval function.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.5.0 (including) 1.5.0 (including)
Mediawiki Mediawiki 1.5.1 (including) 1.5.1 (including)
Mediawiki Mediawiki 1.5.2 (including) 1.5.2 (including)
Mediawiki Mediawiki 1.5_alpha1 (including) 1.5_alpha1 (including)
Mediawiki Mediawiki 1.5_alpha2 (including) 1.5_alpha2 (including)
Mediawiki Mediawiki 1.5_beta1 (including) 1.5_beta1 (including)
Mediawiki Mediawiki 1.5_beta2 (including) 1.5_beta2 (including)
Mediawiki Mediawiki 1.5_beta3 (including) 1.5_beta3 (including)

References