CVE Vulnerabilities

CVE-2006-7223

Published: Sep 14, 2007 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.

Affected Software

Name Vendor Start Version End Version
Xwiki Xwiki 0.9.543 (including) 0.9.543 (including)
Xwiki Xwiki 0.9.790 (including) 0.9.790 (including)
Xwiki Xwiki 0.9.793 (including) 0.9.793 (including)
Xwiki Xwiki 0.9.840 (including) 0.9.840 (including)
Xwiki Xwiki 0.9.1252 (including) 0.9.1252 (including)

References