Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2012/08/31/10 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2012/08/31/6 | Mailing List Patch Third Party Advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330 | Issue Tracking Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=853417 | Issue Tracking Patch Third Party Advisory |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T39587 | Issue Tracking Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-10-26T20:00:00
Updated: 2017-10-26T19:57:01
Reserved: 2012-08-21T00:00:00
Link: CVE-2012-4378
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-10-26T20:29:00.327
Modified: 2017-10-31T21:41:37.977
Link: CVE-2012-4378
JSON object: View
Redhat Information
No data.
CWE