Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2011-0047
Disclosure Date: February 04, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
0
Attacker Value
Unknown
CVE-2011-0003
Disclosure Date: January 11, 2011 (last updated October 04, 2023)
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-1190
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
0
Attacker Value
Unknown
CVE-2010-1189
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
0
Attacker Value
Unknown
CVE-2007-0894
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
0
Attacker Value
Unknown
CVE-2005-4501
Disclosure Date: December 22, 2005 (last updated February 22, 2025)
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.
0
Attacker Value
Unknown
CVE-2005-2396
Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.
0
Attacker Value
Unknown
CVE-2004-2152
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.
0