Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-1610

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.526
EPSS Ranking 97.8%
CVSS Severity
CVSS v2 Score 6.0
References
Products affected by CVE-2014-1610


Contact Us

Shodan ® - All rights reserved