
Security researchers from Checkpoint have identified this vulnerability (CVE-2014-1610), and have discovered that it affects all versions of the software, starting with the 1.8 version. Websites are vulnerable only if a specific non-default setting is enabled.
In accordance with security advisory, an attacker who could exploit this vulnerability could cause changes to files and the system and gain complete server control.
Checkpoint said an attacker could inject malicious code on every page of WikiPedia.org something could setat risk millions of users of the site.
Checkpoint immediately informed the Wikimedia Foundation about the bug. So pJanuary 28, the foundation released patch for this bug.
George is still wondering what he is doing here….


