Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
References
Link Resource
http://www.openwall.com/lists/oss-security/2012/08/31/10 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/08/31/6 Mailing List Patch Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330 Issue Tracking Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=853417 Issue Tracking Patch Third Party Advisory
https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html Patch Vendor Advisory
https://phabricator.wikimedia.org/T39587 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2017-10-26T20:00:00

Updated: 2017-10-26T19:57:01

Reserved: 2012-08-21T00:00:00


Link: CVE-2012-4378

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-10-26T20:29:00.327

Modified: 2017-10-31T21:41:37.977


Link: CVE-2012-4378

JSON object: View

cve-icon Redhat Information

No data.

CWE