CVE-2008-5688: Infoleak

Published Dec 19, 2008
·
Updated

MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which might allow remote attackers to obtain sensitive information via unspecified requests that trigger an uncaught exception.

Affected Software

33 affected components
MediaWiki MediaWiki=1.8.1
MediaWiki MediaWiki=1.8.2
MediaWiki MediaWiki=1.8.3
MediaWiki MediaWiki=1.8.4
MediaWiki MediaWiki=1.8.5
MediaWiki MediaWiki=1.9.0
MediaWiki MediaWiki=1.9.1
MediaWiki MediaWiki=1.9.2
MediaWiki MediaWiki=1.9.3
MediaWiki MediaWiki=1.9.4
MediaWiki MediaWiki=1.9.5
MediaWiki MediaWiki=1.9.6
MediaWiki MediaWiki=1.10.0
MediaWiki MediaWiki=1.10.0-rc1
MediaWiki MediaWiki=1.10.0-rc2
MediaWiki MediaWiki=1.10.1
MediaWiki MediaWiki=1.10.2
MediaWiki MediaWiki=1.10.3
MediaWiki MediaWiki=1.10.4
MediaWiki MediaWiki=1.11
MediaWiki MediaWiki=1.11-rc1
MediaWiki MediaWiki=1.11.1
MediaWiki MediaWiki=1.11.2
MediaWiki MediaWiki=1.12.0
MediaWiki MediaWiki=1.12.0-rc1
MediaWiki MediaWiki=1.12.1
MediaWiki MediaWiki=1.12.2
MediaWiki MediaWiki=1.12.3
MediaWiki MediaWiki=1.13.0
MediaWiki MediaWiki=1.13.0-rc1
MediaWiki MediaWiki=1.13.0-rc2
MediaWiki MediaWiki=1.13.1
MediaWiki MediaWiki=1.13.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MediaWiki to a version that resolves this vulnerability.

    Fixed in 1.13.3
  2. Configuration

    Disable detailed exception output by setting the MediaWiki configuration variable wgShowExceptionDetails to false to avoid disclosing the full installation path in error messages.

    MediaWiki wgShowExceptionDetails = false

Event History

Dec 19, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2008-5688?

CVE-2008-5688 is classified as having a moderate severity level due to the potential exposure of sensitive information.

2

How do I fix CVE-2008-5688?

To fix CVE-2008-5688, you should update to MediaWiki version 1.13.3 or later, where the issue is resolved.

3

What versions of MediaWiki are affected by CVE-2008-5688?

CVE-2008-5688 affects MediaWiki versions from 1.8.1 up to, but not including, 1.13.3.

4

What happens if I do not address CVE-2008-5688?

If CVE-2008-5688 is not addressed, attackers may exploit the vulnerability to obtain sensitive information from the server.

5

What is the impact of enabling wgShowExceptionDetails in relation to CVE-2008-5688?

Enabling wgShowExceptionDetails in MediaWiki can lead to the disclosure of the full installation path in debug messages, increasing information leakage risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203