語系:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=729629
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706601
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742857
https://security-tracker.debian.org/tracker/CVE-2013-2031
https://security-tracker.debian.org/tracker/CVE-2013-2032
https://security-tracker.debian.org/tracker/CVE-2013-4567
https://security-tracker.debian.org/tracker/CVE-2013-4568
https://security-tracker.debian.org/tracker/CVE-2013-4572
https://security-tracker.debian.org/tracker/CVE-2013-6452
https://security-tracker.debian.org/tracker/CVE-2013-6453
https://security-tracker.debian.org/tracker/CVE-2013-6454
https://security-tracker.debian.org/tracker/CVE-2013-6472
https://security-tracker.debian.org/tracker/CVE-2014-1610
https://security-tracker.debian.org/tracker/CVE-2014-2665
https://packages.debian.org/source/wheezy/mediawiki
https://packages.debian.org/source/wheezy/mediawiki-extensions
嚴重性: High
ID: 73256
檔案名稱: debian_DSA-2891.nasl
版本: 1.16
類型: local
代理程式: unix
已發布: 2014/3/31
已更新: 2021/1/11
支援的感應器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus
風險因素: High
分數: 7.4
風險因素: High
基本分數: 7.5
時間分數: 6.2
媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: p-cpe:/a:debian:debian_linux:mediawiki, p-cpe:/a:debian:debian_linux:mediawiki-extensions, cpe:/o:debian:debian_linux:7.0
必要的 KB 項目: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l
可被惡意程式利用: true
可輕鬆利用: Exploits are available
修補程式發佈日期: 2014/3/30
弱點發布日期: 2014/3/30
Core Impact
Metasploit (MediaWiki Thumb.php Remote Command Execution)
Elliot (MediaWiki thumb.php page Parameter Remote Shell Command Injection)
CVE: CVE-2013-2031, CVE-2013-2032, CVE-2013-4567, CVE-2013-4568, CVE-2013-4572, CVE-2013-6452, CVE-2013-6453, CVE-2013-6454, CVE-2013-6472, CVE-2014-1610, CVE-2014-2665
BID: 59594, 59595, 63757, 63760, 63761, 65003, 65223, 66600
DSA: 2891