Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2011-0047

Disclosure Date: February 04, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
0
Attacker Value
Unknown

CVE-2011-0003

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-1190

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
0
Attacker Value
Unknown

CVE-2010-1189

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
0
Attacker Value
Unknown

CVE-2007-0894

Disclosure Date: February 12, 2007 (last updated October 04, 2023)
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
0
Attacker Value
Unknown

CVE-2006-1498

Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.
0
Attacker Value
Unknown

CVE-2006-0322

Disclosure Date: January 19, 2006 (last updated February 22, 2025)
Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."
0