Show filters
373 Total Results
Displaying 221-230 of 373
Sort by:
Attacker Value
Unknown
CVE-2012-4378
Disclosure Date: October 26, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
0
Attacker Value
Unknown
CVE-2012-4379
Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.
0
Attacker Value
Unknown
CVE-2012-4380
Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4382
Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
0
Attacker Value
Unknown
CVE-2014-9487
Disclosure Date: October 17, 2017 (last updated November 26, 2024)
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.
0
Attacker Value
Unknown
CVE-2015-8009
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered Consumers to use another Consumer's credentials by leveraging knowledge of the credentials.
0
Attacker Value
Unknown
CVE-2016-6334
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
0
Attacker Value
Unknown
CVE-2016-6335
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.
0
Attacker Value
Unknown
CVE-2016-6331
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
0
Attacker Value
Unknown
CVE-2016-6333
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
0