Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2011-0047

Disclosure Date: February 04, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
0
Attacker Value
Unknown

CVE-2011-0003

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-1190

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
0
Attacker Value
Unknown

CVE-2010-1189

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
0
Attacker Value
Unknown

CVE-2008-5252

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-0894

Disclosure Date: February 12, 2007 (last updated October 04, 2023)
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
0
Attacker Value
Unknown

CVE-2005-4501

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.
0
Attacker Value
Unknown

CVE-2005-3166

Disclosure Date: October 06, 2005 (last updated February 22, 2025)
Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL.
0
Attacker Value
Unknown

CVE-2005-2396

Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.
0
Attacker Value
Unknown

CVE-2005-1888

Disclosure Date: June 06, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.
0