Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-2787

Опубликовано: 27 апр. 2011
Источник: debian
EPSS Низкий

Описание

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mediawikifixed1:1.15.5-1package
mediawikino-dsalennypackage

Примечания

  • http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-July/000092.html

EPSS

Процентиль: 67%
0.00551
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

nvd
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

github
больше 3 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

EPSS

Процентиль: 67%
0.00551
Низкий