Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-2787

Опубликовано: 27 апр. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

not-affected

1:1.15.5-1
natty

not-affected

oneiric

not-affected

precise

not-affected

quantal

not-affected

Показывать по

Ссылки на источники

EPSS

Процентиль: 67%
0.00551
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

debian
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public cach ...

github
больше 3 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

EPSS

Процентиль: 67%
0.00551
Низкий

4.3 Medium

CVSS2