Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-4381

Опубликовано: 08 фев. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 9.3
CVSS3: 8.1

Описание

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

devel

not-affected

esm-apps/bionic

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1:1.19.14+dfsg-1]]
hardy

ignored

end of life
lucid

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life

Показывать по

EPSS

Процентиль: 86%
0.03103
Низкий

9.3 Critical

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 6 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

CVSS3: 8.1
debian
почти 6 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in t ...

github
почти 4 года назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

EPSS

Процентиль: 86%
0.03103
Низкий

9.3 Critical

CVSS2

8.1 High

CVSS3