CVE-2010-1190

critical

Description

thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.

References

http://www.vupen.com/english/advisories/2010/1001

http://www.vupen.com/english/advisories/2010/0685

http://www.debian.org/security/2010/dsa-2022

http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES

http://secunia.com/advisories/39656

http://secunia.com/advisories/39022

http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html

http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html

Details

Source: Mitre, NVD

Published: 2010-03-31

Updated: 2013-09-13

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical