|
|
| |
|
| |
dokuwiki: cross-site scripting
| Package(s): | dokuwiki |
CVE #(s): | CVE-2012-0283
|
| Created: | August 13, 2012 |
Updated: | October 30, 2012 |
| Description: |
From the Mageia advisory:
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList
function in inc/template.php in DokuWiki before 2012-01-25b allows
remote attackers to inject arbitrary web script or HTML via the ns
parameter in a medialist action to lib/exe/ajax.php |
| Alerts: |
|
( Log in to post comments)
|
|
|