LWN.net Logo

dokuwiki: cross-site scripting

Package(s):dokuwiki CVE #(s):CVE-2012-0283
Created:August 13, 2012 Updated:October 30, 2012
Description: From the Mageia advisory:

Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php

Alerts:
Mageia MGASA-2012-0207 2012-08-12
Fedora FEDORA-2012-16614 2012-10-30
Fedora FEDORA-2012-16605 2012-10-30
Gentoo 201301-07 2013-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds