Vulnerabilities > Mediawiki > Mediawiki > 1.21.1

DATE CVE VULNERABILITY TITLE RISK
2014-05-12 CVE-2013-6454 Cross-Site Scripting vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.
network
mediawiki CWE-79
4.3
2014-05-12 CVE-2013-6453 Improper Input Validation vulnerability in Mediawiki
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
network
low complexity
mediawiki CWE-20
7.5
2014-05-12 CVE-2013-6452 Cross-Site Scripting vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
network
mediawiki CWE-79
4.3
2014-05-12 CVE-2013-4574 Cross-Site Scripting vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to videos.
network
mediawiki CWE-79
4.3
2014-05-12 CVE-2013-4571 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mediawiki
Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 has unspecified impact and remote vectors.
network
low complexity
mediawiki CWE-119
7.5
2014-05-12 CVE-2013-4570 Unspecified vulnerability in Mediawiki
The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to converting Lua data structures to PHP, as demonstrated by passing { [{}] = 1 } to a module function.
network
low complexity
mediawiki
5.0
2014-04-29 CVE-2014-2853 Cross-Site Scripting vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.
network
mediawiki CWE-79
4.3
2014-04-20 CVE-2014-2665 Improper Authentication vulnerability in Mediawiki
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
network
low complexity
mediawiki CWE-287
4.0
2014-01-30 CVE-2014-1610 Improper Input Validation vulnerability in Mediawiki
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
network
mediawiki CWE-20
6.0
2014-01-26 CVE-2013-4304 Improper Authentication vulnerability in multiple products
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.
network
low complexity
brion-vibber mediawiki CWE-287
7.5