Description
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
Remediation
References
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3838)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (5.0.8)
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-28334)
WordPress Plugin Product Reviews Import Export for WooCommerce Cross-Site Request Forgery (1.3.2)