LWN.net Logo

mediawiki: multiple vulnerabilities

Package(s):mediawiki CVE #(s):CVE-2013-4301 CVE-2013-4303
Created:September 16, 2013 Updated:September 23, 2013
Description: From the Mandriva advisory:

Full path disclosure in MediaWiki before 1.20.7, when an invalid language is specified in ResourceLoader (CVE-2013-4301).

An issue with the MediaWiki API in MediaWiki before 1.20.7 where an invalid property name could be used for XSS with older versions of Internet Explorer (CVE-2013-4303).

Alerts:
Mandriva MDVSA-2013:235 2013-09-16
Mageia MGASA-2013-0276 2013-09-13
Fedora FEDORA-2013-15994 2013-09-20
Fedora FEDORA-2013-15984 2013-09-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds