Description
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
Remediation
References
Related Vulnerabilities
Oracle Database Server Improper Access Control Vulnerability (CVE-2026-34312)
Python Numeric Errors Vulnerability (CVE-2008-5031)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4588)
Joomla! Core 1.5.x Session Fixation (1.5.0 - 1.5.15)
WordPress Plugin Conditional Marketing Mailer for WooCommerce Cross-Site Request Forgery (1.5.2)