4.3
CVSSv2

CVE-2007-4828

Published: 12/09/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 up to and including 1.8.4, 1.9.0 up to and including 1.9.3, 1.10.0 up to and including 1.10.1, and the 1.11 development versions prior to 1.11.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.8.2

mediawiki mediawiki 1.8.3

mediawiki mediawiki 1.10.0

mediawiki mediawiki 1.10.1

mediawiki mediawiki 1.11_development

mediawiki mediawiki 1.9.1

mediawiki mediawiki 1.9.2

mediawiki mediawiki 1.8.4

mediawiki mediawiki 1.9.0

mediawiki mediawiki 1.8.0

mediawiki mediawiki 1.8.1

mediawiki mediawiki 1.9.3

Vendor Advisories

Debian Bug report logs - #442255 CVE-2007-4828 XSS in pretty-printing mode Package: mediawiki110; Maintainer for mediawiki110 is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Fri, 14 Sep 2007 12:03:03 UTC Severity: serious Tags: security Fixed in version mediawiki110/1102-1 Done: Romain Beauxis <toot ...