CVE Vulnerabilities

CVE-2005-4031

Published: Dec 06, 2005 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the user language option, which is used as part of a dynamic class name that is processed using the eval function.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.5.0 (including) 1.5.0 (including)
Mediawiki Mediawiki 1.5.1 (including) 1.5.1 (including)
Mediawiki Mediawiki 1.5.2 (including) 1.5.2 (including)
Mediawiki Mediawiki 1.5_alpha1 (including) 1.5_alpha1 (including)
Mediawiki Mediawiki 1.5_alpha2 (including) 1.5_alpha2 (including)
Mediawiki Mediawiki 1.5_beta1 (including) 1.5_beta1 (including)
Mediawiki Mediawiki 1.5_beta2 (including) 1.5_beta2 (including)
Mediawiki Mediawiki 1.5_beta3 (including) 1.5_beta3 (including)

References