CVE-2010-1190
Publication date 31 March 2010
Last updated 24 July 2024
Ubuntu priority
Description
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mediawiki | ||
Patch details
| Package | Patch details |
|---|---|
| mediawiki |