CVE-2009-0737 Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php)
Bug #348858 reported by
Andreas Wenning
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
mediawiki (Ubuntu) |
Fix Released
|
High
|
Andreas Wenning | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned | ||
Intrepid |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: mediawiki
== Upstream description ==
A number of cross-site scripting (XSS) security vulnerabilities were discovered in the web-based installer (config/index.php). These vulnerabilities all require a live installer -- once the installer has been used to install a wiki, it is deactivated.
== Links ==
http://
http://
http://
== Affects ==
jaunty
intrepid
hardy
gutsy (not patchable due to packaging)
dapper (not patchable due to packaging)
CVE References
Changed in mediawiki: | |
assignee: | nobody → andreas-wenning |
importance: | Undecided → High |
status: | New → In Progress |
Changed in mediawiki: | |
status: | In Progress → Fix Committed |
To post a comment you must log in.
Debdiff for hardy, both built and tested locally.