Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.18.5 (including) |
Mediawiki | Mediawiki | 1.18 (including) | 1.18 (including) |
Mediawiki | Mediawiki | 1.18-beta_1 (including) | 1.18-beta_1 (including) |
Mediawiki | Mediawiki | 1.18.0 (including) | 1.18.0 (including) |
Mediawiki | Mediawiki | 1.18.0-rc1 (including) | 1.18.0-rc1 (including) |
Mediawiki | Mediawiki | 1.18.1 (including) | 1.18.1 (including) |
Mediawiki | Mediawiki | 1.18.2 (including) | 1.18.2 (including) |
Mediawiki | Mediawiki | 1.18.3 (including) | 1.18.3 (including) |
Mediawiki | Mediawiki | 1.18.4 (including) | 1.18.4 (including) |
Mediawiki | Ubuntu | lucid | * |
Mediawiki | Ubuntu | precise | * |
Mediawiki | Ubuntu | upstream | * |