[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4036-1 mediawiki -- mediawiki

ID: oval:org.secpod.oval:def:603173Date: (C)2017-12-08   (M)2022-08-31
Class: PATCHFamily: unix




Multiple security vulnerabilities have been discovered in MediaWiki, a website engine for collaborative work: CVE-2017-8808 Cross-site-scripting with non-standard URL escaping and $wgShowExceptionDetails disabled. CVE-2017-8809 Reflected file download in API. CVE-2017-8810 On private wikis the login form didn"t distinguish between login failure due to bad username and bad password. CVE-2017-8811 It was possible to mangle HTML via raw message parameter expansion. CVE-2017-8812 id attributes in headlines allowed raw ">". CVE-2017-8814 Language converter could be tricked into replacing text inside tags. CVE-2017-8815 Unsafe attribute injection via glossary rules in language converter.

Platform:
Debian 9.x
Product:
mediawiki
Reference:
DSA-4036-1
CVE-2017-8808
CVE-2017-8809
CVE-2017-8810
CVE-2017-8811
CVE-2017-8812
CVE-2017-8814
CVE-2017-8815
CVE    7
CVE-2017-8815
CVE-2017-8814
CVE-2017-8809
CVE-2017-8808
...
CPE    3
cpe:/o:debian:debian_linux:9.0
cpe:/a:mediawiki:mediawiki
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies