Vulnerabilities > Mediawiki > Mediawiki > 1.3

DATE CVE VULNERABILITY TITLE RISK
2005-07-27 CVE-2005-2396 Remote Cross-Site Scripting vulnerability in MediaWiki
Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.
network
mediawiki
4.3
2005-06-06 CVE-2005-1888 HTML Injection vulnerability in MediaWiki Page Template
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.
network
mediawiki
4.3
2005-05-02 CVE-2005-1245 HTML Tidy Cross-Site Scripting vulnerability in MediaWiki
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
mediawiki
4.3
2005-02-22 CVE-2005-0535 Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
network
low complexity
mediawiki gentoo
7.5
2004-12-31 CVE-2004-1405 Remote Arbitrary Script Upload vulnerability in MediaWiki
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
network
low complexity
mediawiki
7.5