CVE-2006-2895

Cross-site scripting (XSS) vulnerability in MediaWiki 1.6.0 up to versions before 1.6.7 allows remote attackers to inject arbitrary HTML and web script via the edit form.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.5_r14348:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:12

Type Values Removed Values Added
References () http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-June/000048.html - Patch () http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-June/000048.html - Patch
References () http://secunia.com/advisories/20458 - Patch, Vendor Advisory () http://secunia.com/advisories/20458 - Patch, Vendor Advisory
References () http://svn.wikimedia.org/viewvc/mediawiki/tags/REL1_6_7/phase3/RELEASE-NOTES - Patch () http://svn.wikimedia.org/viewvc/mediawiki/tags/REL1_6_7/phase3/RELEASE-NOTES - Patch
References () http://www.vupen.com/english/advisories/2006/2159 - () http://www.vupen.com/english/advisories/2006/2159 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27029 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27029 -

Information

Published : 2006-06-07 10:02

Updated : 2024-11-21 00:12


NVD link : CVE-2006-2895

Mitre link : CVE-2006-2895

CVE.ORG link : CVE-2006-2895


JSON object : View

Products Affected

mediawiki

  • mediawiki