Vulnerability Name: | CVE-2009-0737 (CCN-48601) | ||||||||||||||||
Assigned: | 2009-02-07 | ||||||||||||||||
Published: | 2009-02-07 | ||||||||||||||||
Updated: | 2009-10-14 | ||||||||||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.2 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-0737 Source: MLIST Type: Patch [MediaWiki-announce] 20090207 MediaWiki releases: security update and new major branch Source: CCN Type: SA33881 MediaWiki Installer Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Vendor Advisory 33881 Source: CONFIRM Type: Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTES Source: CCN Type: MediaWiki Web site MediaWiki release notes Source: CONFIRM Type: Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTES Source: CONFIRM Type: Vendor Advisory http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTES Source: DEBIAN Type: UNKNOWN DSA-1901 Source: DEBIAN Type: DSA-1901 mediawiki1.7 -- several vulnerabilities Source: CCN Type: OSVDB ID: 52034 MediaWiki Installer config/index.php Unspecified Parameter XSS Source: BID Type: Patch 33681 Source: CCN Type: BID-33681 MediaWiki 'config/index.php' Multiple Cross Site Scripting Vulnerabilities Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-0368 Source: XF Type: UNKNOWN mediawiki-configindex-xss(48601) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |