Vulnerability Name: | CVE-2007-4828 (CCN-36558) | ||||||||
Assigned: | 2007-09-10 | ||||||||
Published: | 2007-09-10 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4828 Source: FEDORA Type: UNKNOWN FEDORA-2007-2189 Source: CCN Type: MediaWiki-announce Mailing List, Mon Sep 10 22:11:37 UTC 2007 MediaWiki 1.11.0, 1.10.2, 1.9.4, 1.8.5 released (HTML/XSS API injection) Source: MLIST Type: Patch [MediaWiki-announce] 20070910 MediaWiki 1.11.0, 1.10.2, 1.9.4, 1.8.5 released Source: CCN Type: SA26772 MediaWiki Cross-Site Scripting Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 26772 Source: SECUNIA Type: UNKNOWN 26870 Source: CCN Type: MediaWiki Web site MediaWiki - MediaWiki Source: CCN Type: OSVDB ID: 36946 MediaWiki API pretty-printing mode Unspecified Parameter XSS Source: CCN Type: OSVDB ID: 37336 MediaWiki BotQuery extension Unspecified XSS Source: BID Type: UNKNOWN 25632 Source: CCN Type: BID-25632 MediaWiki API Pretty-Printing Mode Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-3130 Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=287881 Source: XF Type: UNKNOWN mediawiki-prettyprinting-xss(36558) Source: XF Type: UNKNOWN mediawiki-prettyprinting-xss(36558) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |