|
|
| |
|
| |
mediawiki: cross-site scripting
| Package(s): | mediawiki |
CVE #(s): | CVE-2009-0737
|
| Created: | March 2, 2009 |
Updated: | October 5, 2009 |
| Description: |
From the Red Hat bugzilla entry:
Multiple cross-site scripting (XSS) vulnerabilities in the web-based
installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12
before 1.12.4, and 1.13 before 1.13.4, when the installer is in active
use, allow remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| Alerts: |
|
( Log in to post comments)
|
|
|