Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-6728
Description:The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-6728
BugTraq ID: 76334
http://www.securityfocus.com/bid/76334
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165193.html
https://security.gentoo.org/glsa/201510-05
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-August/000179.html
http://www.openwall.com/lists/oss-security/2015/08/12/6
http://www.openwall.com/lists/oss-security/2015/08/27/6




© 1998-2025 E-Soft Inc. All rights reserved.