Vulnerability Name: | CVE-2007-1055 (CCN-32586) | ||||||||
Assigned: | 2007-02-19 | ||||||||
Published: | 2007-02-19 | ||||||||
Updated: | 2018-10-19 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter. Note: this issue might be a duplicate of CVE-2007-0177. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
2.4 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Feb 19 2007 - 22:29:01 CST MediaWiki Cross-site Scripting Source: MITRE Type: CNA CVE-2007-1054 Source: MITRE Type: CNA CVE-2007-1055 Source: OSVDB Type: Broken Link 37343 Source: CCN Type: SA24211 MediaWiki AJAX UTF-7 Cross-Site Scripting Source: SREASON Type: Exploit, Third Party Advisory 2274 Source: CONFIRM Type: Third Party Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES Source: MISC Type: Broken Link, Third Party Advisory http://www.bugsec.com/articles.php?Security=24 Source: CCN Type: MediaWiki Web site MediaWiki - MediaWiki Source: CCN Type: OSVDB ID: 32078 MediaWiki AJAX Support Module UTF-7 XSS Source: CCN Type: OSVDB ID: 37343 MediaWiki AJAX Features index.php rs Parameter XSS Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20070220 MediaWiki Cross-site Scripting Source: XF Type: Third Party Advisory, VDB Entry mediawiki-index-xss(32586) Source: XF Type: UNKNOWN mediawiki-index-xss(32586) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |