Vulnerabilities > Mediawiki > Mediawiki > 1.3.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-12-22 | CVE-2005-4501 | Unspecified vulnerability in Mediawiki MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer. network mediawiki | 4.3 |
2005-10-06 | CVE-2005-3166 | Denial-Of-Service vulnerability in Mediawiki Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL. | 5.0 |
2005-07-27 | CVE-2005-2396 | Remote Cross-Site Scripting vulnerability in MediaWiki Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template. network mediawiki | 4.3 |
2005-06-06 | CVE-2005-1888 | HTML Injection vulnerability in MediaWiki Page Template Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates. network mediawiki | 4.3 |
2005-05-02 | CVE-2005-1245 | HTML Tidy Cross-Site Scripting vulnerability in MediaWiki Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors. network mediawiki | 4.3 |
2005-05-02 | CVE-2005-0536 | Unspecified vulnerability in Mediawiki Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion. | 5.0 |
2005-05-02 | CVE-2005-0534 | Unspecified vulnerability in Mediawiki Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script. network mediawiki | 4.3 |
2005-02-22 | CVE-2005-0535 | Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users. | 7.5 |
2004-12-31 | CVE-2004-2152 | Cross-Site Scripting vulnerability in MediaWiki Raw Page Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML. network mediawiki | 4.3 |
2004-12-31 | CVE-2004-1405 | Remote Arbitrary Script Upload vulnerability in MediaWiki MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code. | 7.5 |