Description
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
Remediation
References
Related Vulnerabilities
Drupal Core 8.x Multiple Vulnerabilities (8.0.0 - 8.1.9)
Apache read beyond bounds via ap_rwrite() Vulnerability (CVE-2022-28614)
Ruby on Rails CVE-2019-5418 Vulnerability (CVE-2019-5418)
WordPress Plugin File Away Multiple Unspecified Vulnerabilities (3.8.4)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)