VDB

CVE-2014-1610

CVE-2014-1610 REJECTED

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.

EPSS 42.78% · 98.6th percentile

Risk Scores

EPSS Score
42.78%
98.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSmediawiki0, 1:1.19.8+dfsg-1, 1:1.19.8+dfsg-2

Timeline

  • CVE Published
  • Feb 2, 2014 PoC Published
  • Feb 20, 2014 PoC Published
  • Feb 22, 2014 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Jul 15, 2022 EPSS Score
  • Apr 16, 2023 EPSS Score
  • Jun 6, 2023 EPSS Score
  • Aug 17, 2024 EPSS Score
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›