|
|
| |
|
| |
mediawiki: multiple vulnerabilities
| Package(s): | mediawiki |
CVE #(s): | CVE-2011-1587
CVE-2011-4360
CVE-2011-4361
|
| Created: | December 19, 2011 |
Updated: | December 21, 2011 |
| Description: |
From the Debian advisory:
CVE-2011-1587:
Masato Kinugawa discovered a cross-site scripting (XSS) issue, which
affects Internet Explorer clients only, and only version 6 and
earlier. Web server configuration changes are required to fix this
issue. Upgrading MediaWiki will only be sufficient for people who use
Apache with AllowOverride enabled.
CVE-2011-4360:
Alexandre Emsenhuber discovered an issue where page titles on private
wikis could be exposed bypassing different page ids to index.php. In the
case of the user not having correct permissions, they will now be redirected
to Special:BadTitle.
CVE-2011-4361:
Tim Starling discovered that action=ajax requests were dispatched to the
relevant function without any read permission checks being done. This could
have led to data leakage on private wikis. |
| Alerts: |
|
( Log in to post comments)
|
|
|