Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2011-0047
Disclosure Date: February 04, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
0
Attacker Value
Unknown
CVE-2011-0003
Disclosure Date: January 11, 2011 (last updated October 04, 2023)
MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-1190
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
0
Attacker Value
Unknown
CVE-2010-1189
Disclosure Date: March 31, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
0
Attacker Value
Unknown
CVE-2008-5252
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-0894
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
0
Attacker Value
Unknown
CVE-2006-1498
Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.
0
Attacker Value
Unknown
CVE-2006-0322
Disclosure Date: January 19, 2006 (last updated February 22, 2025)
Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."
0
Attacker Value
Unknown
CVE-2005-4501
Disclosure Date: December 22, 2005 (last updated February 22, 2025)
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.
0
Attacker Value
Unknown
CVE-2005-3167
Disclosure Date: October 06, 2005 (last updated February 22, 2025)
Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
0