4.3
CVSSv2

CVE-2005-3165

Published: 06/10/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki prior to 1.4.9 allow remote malicious users to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.4.1

mediawiki mediawiki 1.4.3

mediawiki mediawiki 1.4.6

mediawiki mediawiki 1.4_beta3

mediawiki mediawiki 1.4_beta5

mediawiki mediawiki 1.4.7

mediawiki mediawiki 1.4.8

mediawiki mediawiki 1.4_beta1

mediawiki mediawiki 1.4_beta2

mediawiki mediawiki 1.4.2

mediawiki mediawiki 1.4.5

mediawiki mediawiki 1.4_beta4

mediawiki mediawiki 1.4_beta6