Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function. This vulnerability is addressed in the following product release:
MediaWiki, MediaWiki, 1.5.3
Publication date: Tue, 06 Dec 2005 17:03:00 +0000