CVE-2011-0537

MediaWiki < 1.16.2 - Remote Code Execution via Language File Path Traversal

Title source: llm
STIX 2.1

Description

Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Windows and possibly Novell Netware, allow remote attackers to include and execute arbitrary local PHP files via vectors related to a crafted language file and the Language::factory function.

References (8)

Core 8
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0273
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70799
Issue Tracking x_refsource_confirm
https://bugzilla.wikimedia.org/show_bug.cgi?id=27094
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/02/03/3
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/02/01/4
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70798

Scores

EPSS 0.0052
EPSS Percentile 66.9%

Details

CWE
CWE-22
Status published
Products (40)
mediawiki/mediawiki 1.8.0
mediawiki/mediawiki 1.8.1
mediawiki/mediawiki 1.8.2
mediawiki/mediawiki 1.8.3
mediawiki/mediawiki 1.8.4
mediawiki/mediawiki 1.8.5
mediawiki/mediawiki 1.9.0 (2 CPE variants)
mediawiki/mediawiki 1.9.1
mediawiki/mediawiki 1.9.2
mediawiki/mediawiki 1.9.3
... and 30 more
Published Feb 04, 2011
Tracked Since Feb 18, 2026