Secunia Logo
 
CVE Reference: CVE-2008-0460
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0460

Description:
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/39901

SAID
  Secunia Advisory: SA28629
  Secunia Advisory: SA29266

MLIST
  http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-January/000068.html

FEDORA

BID
  28137


Return to the previous page.