CVE-2007-4883

Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a similar issue to CVE-2007-4828.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.7.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:36

Type Values Removed Values Added
References () http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html - Patch () http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html - Patch
References () http://osvdb.org/37336 - () http://osvdb.org/37336 -

Information

Published : 2007-09-14 00:17

Updated : 2024-11-21 00:36


NVD link : CVE-2007-4883

Mitre link : CVE-2007-4883

CVE.ORG link : CVE-2007-4883


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')