CVE-2008-0460

Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.10.2:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.11:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.11.0rc1:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki_botquery_ext:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki_botquery_ext:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:42

Type Values Removed Values Added
References () http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-January/000068.html - () http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-January/000068.html -
References () http://secunia.com/advisories/28629 - Vendor Advisory () http://secunia.com/advisories/28629 - Vendor Advisory
References () http://secunia.com/advisories/29266 - () http://secunia.com/advisories/29266 -
References () http://www.securityfocus.com/bid/28137 - () http://www.securityfocus.com/bid/28137 -
References () http://www.vupen.com/english/advisories/2008/0280 - () http://www.vupen.com/english/advisories/2008/0280 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39901 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/39901 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00147.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00147.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00189.html - () https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00189.html -

Information

Published : 2008-01-25 16:00

Updated : 2024-11-21 00:42


NVD link : CVE-2008-0460

Mitre link : CVE-2008-0460

CVE.ORG link : CVE-2008-0460


JSON object : View

Products Affected

microsoft

  • internet_explorer

mediawiki

  • mediawiki
  • mediawiki_botquery_ext
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')