CVE-2005-2215

MediaWiki < 1.4.6 and 1.5 < beta3 - Cross-Site Scripting via Page Move Template Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_19_sr.html
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14181
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15950

Scores

EPSS 0.0035
EPSS Percentile 57.3%

Details

Status published
Products (9)
mediawiki/mediawiki 1.4.1
mediawiki/mediawiki 1.4.2
mediawiki/mediawiki 1.4.3
mediawiki/mediawiki 1.4.5
mediawiki/mediawiki 1.4_beta6
mediawiki/mediawiki 1.5_alpha1
mediawiki/mediawiki 1.5_alpha2
mediawiki/mediawiki 1.5_beta1
mediawiki/mediawiki 1.5_beta2
Published Jul 12, 2005
Tracked Since Feb 18, 2026