peter bassill · operator
$ cve CVE-2014-1610 JSON

CVE-2014-1610 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 42.8% (pctl 99)

Patch early

A public exploit exists.

Description

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS42.78% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2014-01-30
Last modified2026-06-17

Affected (1)

VendorProduct
mediawikimediawiki

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD