MediaWiki JSON Callback Crafted API Request Information Disclosure

medium Nessus Plugin ID 31346

Synopsis

The remote web server contains a PHP application that is affected by an information disclosure vulnerability.

Description

The version of MediaWiki installed on the remote host is affected by an information disclosure vulnerability. A remote attacker can exploit this via the 'callback' parameter in an API call for JavaScript Object Notation (JSON) formatted results.

Solution

Upgrade to MediaWiki 1.11.2 or later.

See Also

http://www.nessus.org/u?a161ddff

Plugin Details

Severity: Medium

ID: 31346

File Name: mediawiki_json_callback_info_disclosure.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 3/4/2008

Updated: 6/5/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:mediawiki:mediawiki

Required KB Items: www/PHP, installed_sw/MediaWiki

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2008-1318

BID: 28070

CWE: 200

SECUNIA: 29216