[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-2698Date: (C)2012-06-29   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1027179
SECUNIA-49484
OSVDB-82983
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-June/000116.html
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-June/000117.html
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-June/000118.html
http://www.openwall.com/lists/oss-security/2012/06/14/2
https://bugzilla.wikimedia.org/show_bug.cgi?id=36938
https://gerrit.wikimedia.org/r/#/c/7979/1/includes/SkinTemplate.php
https://www.mediawiki.org/wiki/Release_notes/1.17
https://www.mediawiki.org/wiki/Release_notes/1.18
https://www.mediawiki.org/wiki/Release_notes/1.19
mediawiki-index-uselang-xss(76311)

CPE    155
cpe:/a:mediawiki:mediawiki:1.16.2
cpe:/a:mediawiki:mediawiki:1.12.3
cpe:/a:mediawiki:mediawiki:1.4:beta4
cpe:/a:mediawiki:mediawiki:1.12.2
...
CWE    1
CWE-79

© SecPod Technologies