Unrated severityNVD Advisory· Published Dec 6, 2005· Updated Jun 16, 2026
CVE-2005-4031
CVE-2005-4031
Description
Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:mediawiki:mediawiki:1.5.0:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:mediawiki:mediawiki:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5_alpha1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5_alpha2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5_beta2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.5_beta3:*:*:*:*:*:*:*
- (no CPE)range: >=1.5.0, <1.5.3
Patches
Vulnerability mechanics
References
5- secunia.com/advisories/17866nvdPatchVendor Advisory
- sourceforge.net/project/shownotes.phpnvdPatch
- www.securityfocus.com/bid/15703nvdPatch
- www.kb.cert.org/vuls/id/392156nvdUS Government Resource
- www.vupen.com/english/advisories/2005/2726nvd
News mentions
0No linked articles in our index yet.