National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/a:mediawiki:mediawiki:1.3.2
There are 130 matching records.
Displaying matches 121 through 130.
Vuln ID Summary CVSS Severity
CVE-2005-4501

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

Published: December 22, 2005; 04:03:00 PM -05:00
    V2: 4.3 MEDIUM
CVE-2005-3166

Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL.

Published: October 06, 2005; 06:02:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2005-2396

Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.

Published: July 27, 2005; 12:00:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2005-1888

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.

Published: June 06, 2005; 12:00:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2005-0534

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.

Published: May 02, 2005; 12:00:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2005-0536

Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion.

Published: May 02, 2005; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2005-1245

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Published: May 02, 2005; 12:00:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2005-0535

Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.

Published: February 22, 2005; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2004-1405

MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.

Published: December 31, 2004; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2004-2152

Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.

Published: December 31, 2004; 12:00:00 AM -05:00
    V2: 4.3 MEDIUM