FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0047

This CVE name corresponds to:

Entered Topic
2011-02-09 mediawiki -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0047
Phase Assigned(20101221)

Description

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."

References

Source Reference
MLIST [MediaWiki-announce] 20110201 MediaWiki security release 1.16.2
CONFIRM https://bugzilla.wikimedia.org/show_bug.cgi?id=27093
FEDORA FEDORA-2011-5807
FEDORA FEDORA-2011-5812
FEDORA FEDORA-2011-5848
BID 46108
OSVDB 70770
SECUNIA 43142
VUPEN ADV-2011-0273
XF mediawiki-css-comments-xss(65126)