Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-1581
Description:MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-1581
48504
http://secunia.com/advisories/48504
52689
http://www.securityfocus.com/bid/52689
[MediaWiki-announce] 20120322 MediaWiki security and maintenance release 1.17.3
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.html
[MediaWiki-announce] 20120322 MediaWiki security and maintenance release 1.18.2
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.html
[oss-security] 20120322 MediaWiki security and maintenance release 1.18.2
http://www.openwall.com/lists/oss-security/2012/03/22/9
[oss-security] 20120323 CVEs for MediaWiki security and maintenance release 1.18.2
http://www.openwall.com/lists/oss-security/2012/03/24/1
https://bugzilla.wikimedia.org/show_bug.cgi?id=35078
https://bugzilla.wikimedia.org/show_bug.cgi?id=35078
mediawiki-random-numbers-sec-bypass(78910)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78910




© 1998-2025 E-Soft Inc. All rights reserved.