[CVE-2008-4408] XSS attack vulnerability
Bug #290015 reported by
Iain Lane
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
mediawiki (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Iain Lane | ||
Intrepid |
Fix Released
|
Undecided
|
Iain Lane |
Bug Description
Binary package hint: mediawiki
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for mediawiki.
CVE-2008-4408[0]:
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0,
and possibly other versions before 1.13.2 allows remote attackers
to inject arbitrary web script or HTML via the useskin parameter
to an unspecified component.
For further information see:
[0] http://
CVE References
Changed in mediawiki: | |
assignee: | nobody → laney |
status: | New → In Progress |
status: | New → In Progress |
assignee: | nobody → laney |
To post a comment you must log in.
I don't have an exploit for this, I'm afraid.
Tested in Hardy and Intrepid both before and after by creating and updating wikipages, performing various administrative tasks and editing user settings (including skin previews, which is the feature that these patches touch). All seemed to work fine.
Gutsy and Dapper don't appear to be affected as they don't have the same code.