Show filters
373 Total Results
Displaying 331-340 of 373
Sort by:
Attacker Value
Unknown

CVE-2010-1647

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.
0
Attacker Value
Unknown

CVE-2010-1648

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.
0
Attacker Value
Unknown

CVE-2010-1150

Disclosure Date: April 20, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.
0
Attacker Value
Unknown

CVE-2010-1190

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
0
Attacker Value
Unknown

CVE-2010-1189

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
0
Attacker Value
Unknown

CVE-2009-4589

Disclosure Date: January 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.
0
Attacker Value
Unknown

CVE-2009-0737

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-5252

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-5687

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
0
Attacker Value
Unknown

CVE-2008-5250

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page.
0