2.6
CVSSv2

CVE-2009-0737

Published: 25/02/2009 Updated: 14/10/2009
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 prior to 1.6.12, 1.12 prior to 1.12.4, and 1.13 prior to 1.13.4, when the installer is in active use, allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.12.0

mediawiki mediawiki 1.13.0

mediawiki mediawiki 1.13.1

mediawiki mediawiki 1.6.5

mediawiki mediawiki 1.6.6

mediawiki mediawiki 1.12.1

mediawiki mediawiki 1.6.3

mediawiki mediawiki 1.6.4

mediawiki mediawiki 1.6.11

mediawiki mediawiki 1.13.2

mediawiki mediawiki 1.13.3

mediawiki mediawiki 1.6.7

mediawiki mediawiki 1.6.8

mediawiki mediawiki 1.12.2

mediawiki mediawiki 1.12.3

mediawiki mediawiki 1.6.0

mediawiki mediawiki 1.6.1

mediawiki mediawiki 1.6.2

mediawiki mediawiki 1.6.9

mediawiki mediawiki 1.6.10

Vendor Advisories

Several vulnerabilities have been discovered in mediawiki17, a website engine for collaborative work The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-5249 David Remahl discovered that mediawiki17 is prone to a cross-site scripting attack CVE-2008-5250 David Remahl discovered that mediawiki17, when I ...