CVE-2004-1405
EPSS 12.0%Published: 12/31/2004Modified: 4/28/2026
Description
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
Affected packages (1)
- Debian/mediawikifrom 0, < 1.4.9