Total vulnerabilities in the database
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Software | From | Fixed in |
---|---|---|
mediawiki / mediawiki | 1.18-beta_1 | 1.18-beta_1.x |
mediawiki / mediawiki | - | 1.18.5.x |
mediawiki / mediawiki | 1.18.4 | 1.18.4.x |
mediawiki / mediawiki | 1.18 | 1.18.x |
mediawiki / mediawiki | 1.18.2 | 1.18.2.x |
mediawiki / mediawiki | 1.18.3 | 1.18.3.x |
mediawiki / mediawiki | 1.18.0-rc1 | 1.18.0-rc1.x |
mediawiki / mediawiki | 1.18.1 | 1.18.1.x |
mediawiki / mediawiki | 1.18.0 | 1.18.0.x |
mediawiki / mediawiki | 1.19 | 1.19.x |
mediawiki / mediawiki | 1.19-beta_1 | 1.19-beta_1.x |
mediawiki / mediawiki | 1.19.1 | 1.19.1.x |
mediawiki / mediawiki | 1.19-beta_2 | 1.19-beta_2.x |
mediawiki / mediawiki | 1.19.2 | 1.19.2.x |
mediawiki / mediawiki | 1.20 | 1.20.x |