MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
BID:16032
Info
MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
| Bugtraq ID: | 16032 |
| Class: | Design Error |
| CVE: |
CVE-2005-4501 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2005 12:00AM |
| Updated: | Dec 20 2006 10:38PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 MediaWiki MediaWiki 1.5.3 |
| Not Vulnerable: |
MediaWiki MediaWiki 1.5.4 |
Discussion
MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
MediaWiki is prone to a vulnerability that may allow attackers to execute script code in a user's browser.
Security checks related to inline style attributes can be bypassed, facilitating injection of script code to be executed in a user's browser.
MediaWiki 1.5.3 is known to be vulnerable to this issue; other versions may be affected as well.
MediaWiki is prone to a vulnerability that may allow attackers to execute script code in a user's browser.
Security checks related to inline style attributes can be bypassed, facilitating injection of script code to be executed in a user's browser.
MediaWiki 1.5.3 is known to be vulnerable to this issue; other versions may be affected as well.
Exploit / POC
MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
Solution:
The vendor has released MediaWiki 1.5.4 to address this issue.
SUSE Linux has released security advisory SUSE-SR:2006:003 addressing this issue. Please see the referenced advisory for further information.
MediaWiki MediaWiki 1.5.3
Solution:
The vendor has released MediaWiki 1.5.4 to address this issue.
SUSE Linux has released security advisory SUSE-SR:2006:003 addressing this issue. Please see the referenced advisory for further information.
MediaWiki MediaWiki 1.5.3
-
MediaWiki mediawiki-1.5.4.tar.gz
http://prdownloads.sourceforge.net/wikipedia/mediawiki-1.5.4.tar.gz?do wnload
References
MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
References:
References:
- MediaWiki Homepage (MediaWiki)
- Release Name: MediaWiki 1.5.4 (MediaWiki)