CVE-2010-1190

MediaWiki <1.15.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39656
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2022
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0685
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39022
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1001

Scores

EPSS 0.0022
EPSS Percentile 44.5%

Details

CWE
CWE-264
Status published
Products (42)
mediawiki/mediawiki 1.1.0
mediawiki/mediawiki 1.2.0
mediawiki/mediawiki 1.2.1
mediawiki/mediawiki 1.2.2
mediawiki/mediawiki 1.2.3
mediawiki/mediawiki 1.2.4
mediawiki/mediawiki 1.2.5
mediawiki/mediawiki 1.2.6
mediawiki/mediawiki 1.3
mediawiki/mediawiki 1.3.0
... and 32 more
Published Mar 31, 2010
Tracked Since Feb 18, 2026