Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown

CVE-2012-4377

Disclosure Date: October 26, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script or HTML via a File: link to a nonexistent image.
0
Attacker Value
Unknown

CVE-2012-4378

Disclosure Date: October 26, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
0
Attacker Value
Unknown

CVE-2012-4379

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.
0
Attacker Value
Unknown

CVE-2012-4380

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4382

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
0
Attacker Value
Unknown

CVE-2014-9487

Disclosure Date: October 17, 2017 (last updated November 26, 2024)
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.
0
Attacker Value
Unknown

CVE-2014-7295

Disclosure Date: October 07, 2014 (last updated October 05, 2023)
The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css.
0
Attacker Value
Unknown

CVE-2014-7199

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.
0
Attacker Value
Unknown

CVE-2014-5243

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
0
Attacker Value
Unknown

CVE-2014-5241

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set.
0