>> MediaWiki JSON Callback Parameter Information Disclosure Vulnerability
Title : MediaWiki JSON Callback Parameter Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-0732 CVE ID : CVE-2008-1318
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-03
Technical Description
A vulnerability has been identified in MediaWiki, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an error when handling the callback parameter for JSON-formatted results in the API, which could be exploited by attackers to disclose sensitive information via a specially crafted request.