[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3011-1 mediawiki -- mediawiki

ID: oval:org.secpod.oval:def:601762Date: (C)2014-09-04   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that MediaWiki, a website engine for collaborative work, is vulnerable to JSONP injection in Flash and clickjacking between OutputPage and ParserOutput . The vulnerabilities are addressed by upgrading MediaWiki to the new upstream version 1.19.18, which includes additional changes.

Platform:
Debian 7.0
Product:
mediawiki
Reference:
DSA-3011-1
CVE-2014-5241
CVE-2014-5243
CVE    2
CVE-2014-5241
CVE-2014-5243
CPE    52
cpe:/a:mediawiki:mediawiki:1.21.10
cpe:/a:mediawiki:mediawiki:1.19.12
cpe:/a:mediawiki:mediawiki:1.19.13
cpe:/a:mediawiki:mediawiki:1.19.14
...

© SecPod Technologies