Vulnerability Name: | CVE-2008-5250 (CCN-47385) | ||||||||||||||||||||
Assigned: | 2008-12-15 | ||||||||||||||||||||
Published: | 2008-12-15 | ||||||||||||||||||||
Updated: | 2009-10-14 | ||||||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page. | ||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2008-5250 Source: SUSE Type: UNKNOWN SUSE-SR:2009:004 Source: CCN Type: MediaWiki-announce Mailing List, Mon Dec 15 11:09:28 UTC 2008 MediaWiki 1.13.3, 1.12.2, 1.6.11 security update Source: MLIST Type: Patch, Vendor Advisory [mediawiki-announce] 20081215 MediaWiki 1.13.3, 1.12.2, 1.6.11 security update Source: CCN Type: SA33133 MediaWiki Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 33133 Source: SECUNIA Type: UNKNOWN 33349 Source: DEBIAN Type: UNKNOWN DSA-1901 Source: DEBIAN Type: DSA-1901 mediawiki1.7 -- several vulnerabilities Source: CCN Type: MediaWiki Web site MediaWiki Source: BID Type: UNKNOWN 32844 Source: CCN Type: BID-32844 MediaWiki Cross Site Scripting And Multiple HTML Injection Vulnerabilities Source: XF Type: UNKNOWN mediawiki-uploads-xss(47385) Source: FEDORA Type: UNKNOWN FEDORA-2008-11688 Source: FEDORA Type: UNKNOWN FEDORA-2008-11802 Source: SUSE Type: SUSE-SR:2009:004 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
Vulnerability Name: | CVE-2008-5250 (CCN-47386) | ||||||||||||||||||||
Assigned: | 2008-12-15 | ||||||||||||||||||||
Published: | 2008-12-15 | ||||||||||||||||||||
Updated: | 2008-12-15 | ||||||||||||||||||||
Summary: | MediaWiki is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by certain SVG scripts. If SVG uploads are enabled, a remote attacker could exploit this vulnerability using an unknown parameter to inject malicious script into a Web page that would be executed in a victim's SVG-enabled Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. | ||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2008-5250 Source: CCN Type: MediaWiki-announce Mailing List, Mon Dec 15 11:09:28 UTC 2008 MediaWiki 1.13.3, 1.12.2, 1.6.11 security update Source: CCN Type: SA33133 MediaWiki Multiple Vulnerabilities Source: DEBIAN Type: DSA-1901 mediawiki1.7 -- several vulnerabilities Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: BID-32844 MediaWiki Cross Site Scripting And Multiple HTML Injection Vulnerabilities Source: XF Type: UNKNOWN mediawiki-svguploads-xss(47386) Source: SUSE Type: SUSE-SR:2009:004 SUSE Security Summary Report | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |