CVE-2014-9277
MediaWiki <1.19.22, 1.20.x-1.22.x<1.22.14, 1.23.x<1.23.7 - Code Inj...
Title source: llmDescription
The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1031301
Exploit x_refsource_confirm
https://phabricator.wikimedia.org/T73478
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/03/9
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/04/16
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2014/dsa-3100
Patch, Vendor Advisory mailing-list
x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html
Scores
EPSS
0.0086
EPSS Percentile
75.3%
Details
CWE
CWE-77
Status
published
Products (42)
mediawiki/mediawiki
1.20
mediawiki/mediawiki
1.20.1
mediawiki/mediawiki
1.20.2
mediawiki/mediawiki
1.20.3
mediawiki/mediawiki
1.20.4
mediawiki/mediawiki
1.20.5
mediawiki/mediawiki
1.20.6
mediawiki/mediawiki
1.20.7
mediawiki/mediawiki
1.20.8
mediawiki/mediawiki
1.21
... and 32 more
Published
Jan 04, 2015
Tracked Since
Feb 18, 2026