MediaWiki Unspecified Cross-Site Scripting Vulnerability
BID:12444
Info
MediaWiki Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 12444 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2005 12:00AM |
| Updated: | Feb 04 2005 12:00AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
MediaWiki MediaWiki 1.3.9 MediaWiki MediaWiki 1.3.8 MediaWiki MediaWiki 1.3.7 MediaWiki MediaWiki 1.3.6 MediaWiki MediaWiki 1.3.5 MediaWiki MediaWiki 1.3.4 MediaWiki MediaWiki 1.3.3 MediaWiki MediaWiki 1.3.2 MediaWiki MediaWiki 1.3.1 MediaWiki MediaWiki 1.3 |
| Not Vulnerable: |
MediaWiki MediaWiki 1.3.10 |
Discussion
MediaWiki Unspecified Cross-Site Scripting Vulnerability
An unspecified remote cross-site scripting vulnerability affects MediaWiki. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in dynamically generated Web page content.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An unspecified remote cross-site scripting vulnerability affects MediaWiki. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in dynamically generated Web page content.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
MediaWiki Unspecified Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
MediaWiki Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has provided and upgrade dealing with this issue.
MediaWiki MediaWiki 1.3
MediaWiki MediaWiki 1.3.1
MediaWiki MediaWiki 1.3.2
MediaWiki MediaWiki 1.3.3
MediaWiki MediaWiki 1.3.4
MediaWiki MediaWiki 1.3.5
MediaWiki MediaWiki 1.3.6
MediaWiki MediaWiki 1.3.7
MediaWiki MediaWiki 1.3.8
MediaWiki MediaWiki 1.3.9
Solution:
The vendor has provided and upgrade dealing with this issue.
MediaWiki MediaWiki 1.3
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.1
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.2
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.3
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.4
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.5
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.6
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.7
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.8
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
MediaWiki MediaWiki 1.3.9
-
MediaWiki MediaWiki 1.3.10
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.3.10.tar.gz?d ownload
References
MediaWiki Unspecified Cross-Site Scripting Vulnerability
References:
References:
- MediaWiki 1.3.10 Release Notes (MediaWiki)
- MediaWiki Homepage (MediaWiki)