Логотип exploitDog
bind:CVE-2014-9277
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-9277

Количество 4

Количество 4

ubuntu логотип

CVE-2014-9277

около 11 лет назад

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-9277

около 11 лет назад

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-9277

около 11 лет назад

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki bef ...

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-p3m7-7j6c-hwc3

больше 3 лет назад

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-9277

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

CVSS2: 7.5
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9277

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

CVSS2: 7.5
1%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9277

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki bef ...

CVSS2: 7.5
1%
Низкий
около 11 лет назад
github логотип
GHSA-p3m7-7j6c-hwc3

The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу