4.3
CVSSv2

CVE-2008-4408

Published: 03/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions prior to 1.13.2 allows remote malicious users to inject arbitrary web script or HTML via the useskin parameter to an unspecified component.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.12.0

mediawiki mediawiki 1.13.1

Vendor Advisories

Debian Bug report logs - #501115 CVE-2008-4408: XSS in mediawiki Package: mediawiki; Maintainer for mediawiki is Kunal Mehta <legoktm@debianorg>; Source for mediawiki is src:mediawiki (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 4 Oct 2008 08:57:01 UTC Severity: impor ...