MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/08/31/6 | mailing list third party advisory patch |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html | mailing list patch vendor advisory |
http://www.openwall.com/lists/oss-security/2012/08/31/10 | mailing list third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=853440 | issue tracking |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330 | issue tracking third party advisory |
https://phabricator.wikimedia.org/T41824 | issue tracking vendor advisory |