Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.
Link | Tags |
---|---|
http://sourceforge.net/project/shownotes.php?release_id=352777 | patch |
http://secunia.com/advisories/16932 | patch vendor advisory third party advisory |
http://lwn.net/Articles/153906/ | vendor advisory |