CVE-2007-0894: Medium severity MediaWiki MediaWiki vulnerability
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0894?
CVE-2007-0894 has a moderate severity as it allows attackers to obtain sensitive information from the affected MediaWiki versions.
How do I fix CVE-2007-0894?
To fix CVE-2007-0894, upgrade MediaWiki to version 1.9.2 or later.
What versions of MediaWiki are affected by CVE-2007-0894?
CVE-2007-0894 affects MediaWiki versions prior to 1.9.2, including all versions from 1.1.0 to 1.8.1.
What information can be leaked due to CVE-2007-0894?
CVE-2007-0894 can leak the installation path of the MediaWiki instance through direct access to certain skin dependency files.
Is there a public exploit for CVE-2007-0894?
While there are no widely known public exploits for CVE-2007-0894, the vulnerability itself poses a risk of information disclosure.