Unrated severityNVD Advisory· Published Nov 9, 2015· Updated May 6, 2026
CVE-2015-8005
CVE-2015-8005
Description
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Affected products
8cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: <=1.23.10
- cpe:2.3:a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.htmlnvdPatchVendor Advisory
- phabricator.wikimedia.org/T108616nvdVendor Advisory
- www.securitytracker.com/id/1034028nvd
News mentions
0No linked articles in our index yet.