Vulnerability Name: | CVE-2007-0177 (CCN-31359) | ||||||||
Assigned: | 2007-01-09 | ||||||||
Published: | 2007-01-09 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0177 Source: OSVDB Type: UNKNOWN 31525 Source: CCN Type: SA23647 MediaWiki AJAX "rs" Cross-Site Scripting Source: SECUNIA Type: Vendor Advisory 23647 Source: SECUNIA Type: UNKNOWN 24889 Source: CCN Type: SourceForge.net MediaWiki 1.6.9, 1.7.2, 1.8.3, 1.9.0rc2 released Source: CONFIRM Type: Patch, Vendor Advisory http://sourceforge.net/forum/forum.php?forum_id=652721 Source: CONFIRM Type: Patch, Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES Source: CONFIRM Type: Patch, Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES Source: CONFIRM Type: Patch, Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES Source: CONFIRM Type: Patch, Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES Source: SUSE Type: UNKNOWN SUSE-SR:2007:006 Source: CCN Type: OSVDB ID: 31525 MediaWiki AJAX Support Module Unspecified XSS Source: CCN Type: OSVDB ID: 37343 MediaWiki AJAX Features index.php rs Parameter XSS Source: BID Type: Patch, Vendor Advisory 21956 Source: CCN Type: BID-21956 MediaWiki AJAX Index.PHP Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-0096 Source: XF Type: UNKNOWN mediawiki-ajax-unspecified-xss(31359) Source: XF Type: UNKNOWN mediawiki-ajax-unspecified-xss(31359) Source: SUSE Type: SUSE-SR:2007:006 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |