From a9896e3669113734fd8e8a2a53bf49f2211fd8ed Mon Sep 17 00:00:00 2001 From: miwi Date: Fri, 19 Dec 2008 20:59:59 +0000 Subject: - Document mediawiki -- multiple vulnerabilities --- security/vuxml/vuln.xml | 51 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 612ab0bc953a..6d847f3e05d9 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,57 @@ Note: Please add new entries to the beginning of this file. --> + + mediawiki -- multiple vulnerabilities + + + mediawiki + 1.6.01.6.11 + 1.12.01.12.3 + 1.13.01.13.3 + + + + +

The MediaWiki development team reports:

+
+

Certain unspecified input is not properly sanitised before being + returned to the user. This can be exploited to execute arbitrary HTML + and script code in a user's browser session in context of an affected + site.

+

Certain unspecified input related to uploads is not properly + sanitised before being used. This can be exploited to inject arbitrary + HTML and script code, which will be executed in a user's browser + session in context of an affected site when a malicious data is + opened. Successful exploitation may require that uploads are enabled + and the victim uses an Internet Explorer based browser.

+

Certain SVG scripts are not properly sanitised before being used. + This can be exploited to inject arbitrary HTML and script code, which + will be executed in a user's browser session in context of an affected + site when a malicious data is opened. Successful exploitation may require + that SVG uploads are enabled and the victim uses a browser supporting SVG + scripting.

+

The application allows users to perform certain actions via HTTP + requests without performing any validity checks to verify the + requests. This can be exploited to perform certain operations when a + logged in user visits a malicious site.

+
+ +
+ + CVE-2008-5249 + CVE-2008-5250 + CVE-2008-5252 + http://secunia.com/advisories/33133/ + http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html + + + 2008-12-15 + 2008-12-19 + +
+ drupal -- multiple vulnerabilities -- cgit