Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jackmcbarn

#39370de 53,630
6.9CVSS total
Vulnerabilidades · 2
Baixa
1
Média
1
PT-2015-5989
4.3
2015-04-09
Mediawiki · Mediawiki Scribunto Extension · CVE-2015-2939
**Name of the Vulnerable Software and Affected Versions** MediaWiki Scribunto extension (affected versions not specified) **Description** A cross-site scripting (XSS) issue exists due to improper handling of a function name in a Lua error backtrace, allowing remote attackers to inject arbitrary web script or HTML. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2015-4252
2.6
2014-12-09
Wikimedia · Mediawiki · CVE-2014-9507
**Name of the Vulnerable Software and Affected Versions** MediaWiki versions 1.21.x through 1.23.x before 1.23.7 MediaWiki version 1.22.x before 1.22.14 **Description** The issue allows remote attackers to conduct cross-site scripting (XSS) attacks by setting the content model for a revision to JS when the `$wgContentHandlerUseDB` variable is enabled. **Recommendations** For MediaWiki versions 1.21.x, update to a version after 1.23.7 or apply the necessary configuration changes to disable the `$wgContentHandlerUseDB` variable. For MediaWiki version 1.22.x before 1.22.14, update to version 1.22.14 or later. For MediaWiki version 1.23.x before 1.23.7, update to version 1.23.7 or later.