Vulnerabilities > CVE-2007-1054 - Cross-Site Scripting vulnerability in Mediawiki

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
mediawiki
nessus

Summary

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer. Successful exploitation requires that "$wgUseAjax" is enabled

Vulnerable Configurations

Part Description Count
Application
Mediawiki
114

Nessus

NASL familyFedora Local Security Checks
NASL idFEDORA_2007-1442.NASL
descriptionThis update fixes the following vulnerability :
last seen2020-06-01
modified2020-06-02
plugin id27715
published2007-11-06
reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/27715
titleFedora 7 : mediawiki-1.9.3-34.0.2.fc7 (2007-1442)