Логотип exploitDog
bind:CVE-2012-4381
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-4381

Количество 4

Количество 4

ubuntu логотип

CVE-2012-4381

около 6 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2012-4381

около 6 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2012-4381

около 6 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in t ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-794f-724h-wf37

почти 4 года назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

CVSS3: 8.1
3%
Низкий
около 6 лет назад
nvd логотип
CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

CVSS3: 8.1
3%
Низкий
около 6 лет назад
debian логотип
CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in t ...

CVSS3: 8.1
3%
Низкий
около 6 лет назад
github логотип
GHSA-794f-724h-wf37

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу