|
|
Log in / Subscribe / Register

mediawiki: multiple vulnerabilities

Package(s):mediawiki CVE #(s):CVE-2014-2242 CVE-2014-2243 CVE-2014-2244
Created:March 10, 2014 Updated:March 12, 2014
Description: From the CVE entries:

includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element. (CVE-2014-2242).

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses. (CVE-2014-2243).

Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php. (CVE-2014-2244).

Alerts:
Gentoo 201502-04 mediawiki 2015-02-07
Mandriva MDVSA-2014:057 mediawiki 2014-03-13
Fedora FEDORA-2014-3344 mediawiki 2014-03-11
Fedora FEDORA-2014-3338 mediawiki 2014-03-11
Mageia MGASA-2014-0124 mediawiki 2014-03-07

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds