Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-8625
Description:MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-8625
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.html
http://www.openwall.com/lists/oss-security/2015/12/21/8
http://www.openwall.com/lists/oss-security/2015/12/23/7




© 1998-2025 E-Soft Inc. All rights reserved.