Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1766
Description:includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1766
44684
http://secunia.com/advisories/44684
47722
http://www.securityfocus.com/bid/47722
FEDORA-2011-6774
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060496.html
FEDORA-2011-6775
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060507.html
FEDORA-2011-6781
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060435.html
[mediawiki-announce] 20110505 MediaWiki security release 1.16.5
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-May/000098.html
https://bugzilla.redhat.com/show_bug.cgi?id=702512
https://bugzilla.redhat.com/show_bug.cgi?id=702512
https://bugzilla.wikimedia.org/show_bug.cgi?id=28639
https://bugzilla.wikimedia.org/show_bug.cgi?id=28639




© 1998-2025 E-Soft Inc. All rights reserved.