CVE-2015-8005
Published Nov 9, 2015
Last updated 9 years ago
Overview
- Description
- MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE35D692-87E9-4982-AA23-27EBD5E5EEE1", "versionEndIncluding": "1.23.10" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B21EB21-AE87-48BF-B4A1-5E63A2E116B4" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6C00423-B3FE-485A-9014-22F409DBD377" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E90C95FB-71CA-4CA1-935D-58A08244A81F" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DDBD41F-C2D5-4D7C-B069-FBC2C8EBB81C" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9129F374-93CB-43CE-A3B2-DB6483514F32" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE125142-10A2-4ACF-9BA4-44E63C1E5DB6" }, { "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF21D6EE-CEAC-42A7-99B6-D9D033E1FEC6" } ], "operator": "OR" } ] } ]