PT-2013-1481 · Wikiwig+1 · Wikiwig+1

Hanno Böck

·

Published

2013-11-05

·

Updated

2013-11-07

·

CVE-2011-5267

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Xinha versions prior to the fixed version WikiWig version 5.01
Description The issue is related to multiple cross-site scripting (XSS) vulnerabilities in the SpellChecker module. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the to p dict or to r list parameters in the spell-check-savedicts.php file.
Recommendations For Xinha, update to a version that includes the fix for this issue. For WikiWig version 5.01, consider disabling the SpellChecker module until a patch is available. As a temporary workaround, restrict access to the spell-check-savedicts.php file to minimize the risk of exploitation. Avoid using the to p dict and to r list parameters in the affected module until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5267

Affected Products

Wikiwig
Xinha