mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
19 lines
950 B
Markdown
19 lines
950 B
Markdown
### [CVE-2010-1150](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1150)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_3/phase3/RELEASE-NOTES
|
|
- http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_16_0beta2/phase3/RELEASE-NOTES
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|