Description
The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.
Remediation
References
Related Vulnerabilities
WordPress Plugin Quote-O-Matic SQL Injection (1.0.5)
WordPress Plugin BuddyPress Multiple Security Bypass Vulnerabilities (7.2.1)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0.1)
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111)