CVE Vulnerabilities

CVE-2007-0177

Published: Jan 11, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.6.0 (including) 1.6.0 (including)
Mediawiki Mediawiki 1.6.1 (including) 1.6.1 (including)
Mediawiki Mediawiki 1.6.2 (including) 1.6.2 (including)
Mediawiki Mediawiki 1.6.3 (including) 1.6.3 (including)
Mediawiki Mediawiki 1.6.4 (including) 1.6.4 (including)
Mediawiki Mediawiki 1.6.5 (including) 1.6.5 (including)
Mediawiki Mediawiki 1.6.5_r14348 (including) 1.6.5_r14348 (including)
Mediawiki Mediawiki 1.6.6 (including) 1.6.6 (including)
Mediawiki Mediawiki 1.7.0 (including) 1.7.0 (including)
Mediawiki Mediawiki 1.7.1 (including) 1.7.1 (including)
Mediawiki Mediawiki 1.8.0 (including) 1.8.0 (including)
Mediawiki Mediawiki 1.8.1 (including) 1.8.1 (including)
Mediawiki Mediawiki 1.8.2 (including) 1.8.2 (including)
Mediawiki Mediawiki 1.9.0-rc2 (including) 1.9.0-rc2 (including)
Mediawiki Ubuntu dapper *
Mediawiki Ubuntu edgy *
Mediawiki Ubuntu feisty *
Mediawiki Ubuntu upstream *

References