VWE-2013-0228-4 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2013-0228-4
This page is a chapter in Info Known Vulnerabilities

This page has been seen 8,629 times.

    • Created by on
Common NameNone
VWE-IDVWE-2013-0228-4
Related ReportNone
SeverityExtreme
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionArbitrary code execution. By passing specially-crafted text content through the text to URL encoder, such as when processing wiki title submissions, a malicious user can execute arbitrary PHP code on the server. Does not affect Lite versions.
DiscoveredJanuary 14, 2013
ResolvedJanuary 8, 2013
Patches Available3.0.20
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.

Notes

For some inexplicable reason, this was treated as a standard bug at the time it was discovered, so other vulnerable versions never received patches. This decision is strange because the similar issue VWE-2012-0205 was addressed in the same time period, but was patched in multiple versions.

In addition, this issue was addressed in an existing patch that had already been released, resulting in some users likely not benefitting from the fixes.