First published: Fri Dec 31 2004(Updated: )
SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execute arbitrary SQL commands via SpecialMaintenance.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | =1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2186 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2004-2186, upgrade MediaWiki to a version later than 1.3.5 that does not contain this vulnerability.
CVE-2004-2186 specifically affects MediaWiki version 1.3.5.
CVE-2004-2186 is an SQL injection vulnerability that allows attackers to manipulate SQL queries executed by the application.
The risks associated with CVE-2004-2186 include unauthorized access to database information, data corruption, and the possibility of a complete system compromise.