Candidate: CVE-2012-1580 PublicDate: 2012-09-09 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1580 http://www.openwall.com/lists/oss-security/2012/03/23 Description: Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files. Ubuntu-Description: Notes: micahg> Debian maintainer said 1.15 isn't affected, see 1:1.15.5-9 changelog Bugs: https://bugzilla.wikimedia.org/show_bug.cgi?id=35317 Priority: low Discovered-by: Jan Schejbal Assigned-to: CVSS: Patches_mediawiki: upstream_mediawiki: needs-triage hardy_mediawiki: ignored (reached end-of-life) lucid_mediawiki: not-affected (1.15.x) maverick_mediawiki: ignored (reached end-of-life) natty_mediawiki: not-affected (1.15.x) oneiric_mediawiki: not-affected (1.15.x) precise_mediawiki: not-affected (1.15.x) quantal_mediawiki: not-affected (1.15.x) raring_mediawiki: not-affected (1.15.x) devel_mediawiki: not-affected (1.15.x)