MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API, (2) enhanced RecentChanges, and (3) user watchlists.
References
Link | Resource |
---|---|
http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000138.html | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2014-05-12T14:00:00
Updated: 2014-05-12T13:57:00
Reserved: 2013-11-04T00:00:00
Link: CVE-2013-6472
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-05-12T14:55:06.400
Modified: 2014-05-13T14:43:14.867
Link: CVE-2013-6472
JSON object: View
Redhat Information
No data.
CWE