Description
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Simple Shopping Cart Cross-Site Scripting (4.6.1)
OpenSSL Other Vulnerability (CVE-2009-1386)
WordPress Plugin Comment Rating Cross-Site Request Forgery (2.9.20)
WordPress Plugin Anti Plagiarism Cross-Site Scripting (3.60)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5478)