Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

Parameters injection in SyntaxHighlight results in multiple vulnerabilities

Disclosure Date: April 13, 2018 (last updated November 26, 2024)
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
0
Attacker Value
Unknown

CVE-2016-6334

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
0
Attacker Value
Unknown

CVE-2016-6335

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.
0
Attacker Value
Unknown

CVE-2016-6331

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
0
Attacker Value
Unknown

CVE-2016-6333

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
0
Attacker Value
Unknown

CVE-2016-6337

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
0
Attacker Value
Unknown

CVE-2016-6332

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
0
Attacker Value
Unknown

CVE-2016-6336

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitrary file revisions by using Special:Undelete.
0