MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
BID:13301
Info
MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13301 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2005 12:00AM |
| Updated: | Apr 21 2005 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
MediaWiki MediaWiki 1.4 beta5 MediaWiki MediaWiki 1.4 beta4 MediaWiki MediaWiki 1.4 beta3 MediaWiki MediaWiki 1.4 beta2 MediaWiki MediaWiki 1.4 beta1 MediaWiki MediaWiki 1.3.11 MediaWiki MediaWiki 1.3.10 MediaWiki MediaWiki 1.3.9 MediaWiki MediaWiki 1.3.8 MediaWiki MediaWiki 1.3.7 MediaWiki MediaWiki 1.3.6 MediaWiki MediaWiki 1.3.5 MediaWiki MediaWiki 1.3.4 MediaWiki MediaWiki 1.3.3 MediaWiki MediaWiki 1.3.2 MediaWiki MediaWiki 1.3.1 MediaWiki MediaWiki 1.3 |
| Not Vulnerable: | |
Discussion
MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
MediaWiki is prone to an unspecified cross-site scripting vulnerability. An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Versions of MediaWiki prior to 1.4.2 are vulnerable.
MediaWiki is prone to an unspecified cross-site scripting vulnerability. An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Versions of MediaWiki prior to 1.4.2 are vulnerable.
Exploit / POC
MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
Solution:
The vendor has released MediaWiki 1.4.2 to address this issue.
MediaWiki MediaWiki 1.3
MediaWiki MediaWiki 1.3.1
MediaWiki MediaWiki 1.3.10
MediaWiki MediaWiki 1.3.11
MediaWiki MediaWiki 1.3.2
MediaWiki MediaWiki 1.3.3
MediaWiki MediaWiki 1.3.4
MediaWiki MediaWiki 1.3.5
MediaWiki MediaWiki 1.3.6
MediaWiki MediaWiki 1.3.7
MediaWiki MediaWiki 1.3.8
MediaWiki MediaWiki 1.3.9
MediaWiki MediaWiki 1.4 beta3
MediaWiki MediaWiki 1.4 beta2
MediaWiki MediaWiki 1.4 beta4
MediaWiki MediaWiki 1.4 beta1
MediaWiki MediaWiki 1.4 beta5
Solution:
The vendor has released MediaWiki 1.4.2 to address this issue.
MediaWiki MediaWiki 1.3
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.1
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.10
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.11
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.2
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.3
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.4
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.5
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.6
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.7
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.8
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.3.9
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.4 beta3
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.4 beta2
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.4 beta4
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.4 beta1
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
MediaWiki MediaWiki 1.4 beta5
-
MediaWiki mediawiki-1.4.2.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.4.2.tar.gz?do wnload
References
MediaWiki Unspecified HTML Tidy Cross-Site Scripting Vulnerability
References:
References:
- MediaWiki 1.4.2 Release Notes (MediaWiki)
- MediaWiki Homepage (MediaWiki)