CVE-2017-0372
CRITICALMediaWiki < 1.23.16, 1.27.3, 1.28.2 - Parameter Injection in SyntaxHighlight Extension
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0372.
Includes Metasploit module exploits/multi/http/mediawiki_syntaxhighlight.
AI-analyzed exploit summary This Metasploit module exploits an option injection vulnerability in the MediaWiki SyntaxHighlight extension to create and execute a PHP file in the document root. It leverages the 'cssfile' and 'classprefix' parameters to inject malicious PHP code, achieving remote code execution.
Description
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Exploits (1)
This Metasploit module exploits an option injection vulnerability in the MediaWiki SyntaxHighlight extension to create and execute a PHP file in the document root. It leverages the 'cssfile' and 'classprefix' parameters to inject malicious PHP code, achieving remote code execution.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H