Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1150

Опубликовано: 20 апр. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6

Описание

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

1:1.15.1-1ubuntu2
hardy

released

1:1.11.2-2ubuntu0.5
intrepid

released

1:1.12.0-2ubuntu0.5
jaunty

released

1:1.13.3-1ubuntu2.2
karmic

released

1:1.15.0-1.1ubuntu0.2
upstream

released

1.15.3

Показывать по

EPSS

Процентиль: 61%
0.00413
Низкий

6 Medium

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.

nvd
больше 15 лет назад

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.

debian
больше 15 лет назад

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not proper ...

github
больше 3 лет назад

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.

EPSS

Процентиль: 61%
0.00413
Низкий

6 Medium

CVSS2