MediaWiki Multiple Remote Input Validation Vulnerabilities
BID:11416
Info
MediaWiki Multiple Remote Input Validation Vulnerabilities
| Bugtraq ID: | 11416 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2004 12:00AM |
| Updated: | Oct 14 2004 12:00AM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
MediaWiki MediaWiki 1.3.5 |
| Not Vulnerable: |
MediaWiki MediaWiki 1.3.6 |
Discussion
MediaWiki Multiple Remote Input Validation Vulnerabilities
MediaWiki is reported prone to multiple cross-site scripting, HTML injection, and SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input data.
HTML injection, and cross-site scripting vulnerabilities allow for attacker-supplied HTML and script code to be executed in the victims browser in the context of the affected site.
SQL injection vulnerabilities allow attackers to manipulate SQL queries, potentially revealing or corrupting sensitive database data. This issue may also facilitate attacks against the underlying database software.
These vulnerabilities are reported to exist in MediaWiki version 1.3.5, but other versions are also possibly affected.
MediaWiki is reported prone to multiple cross-site scripting, HTML injection, and SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input data.
HTML injection, and cross-site scripting vulnerabilities allow for attacker-supplied HTML and script code to be executed in the victims browser in the context of the affected site.
SQL injection vulnerabilities allow attackers to manipulate SQL queries, potentially revealing or corrupting sensitive database data. This issue may also facilitate attacks against the underlying database software.
These vulnerabilities are reported to exist in MediaWiki version 1.3.5, but other versions are also possibly affected.
Exploit / POC
MediaWiki Multiple Remote Input Validation Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
MediaWiki Multiple Remote Input Validation Vulnerabilities
Solution:
The vendor has released version 1.3.6 to address these issues:
MediaWiki MediaWiki 1.3.5
Solution:
The vendor has released version 1.3.6 to address these issues:
MediaWiki MediaWiki 1.3.5
-
MediaWiki mediawiki-1.3.6.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.6.tar.gz?do wnload
References
MediaWiki Multiple Remote Input Validation Vulnerabilities
References:
References:
- MediaWiki 1.3.6 Release Notes (MediaWiki)
- MediaWiki Homepage (MediaWiki)