Description
Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Moshe Ben-Abu · textwebappsphp
https://www.exploit-db.com/exploits/29404
References (12)
Core 12
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0096
Patch, Vendor Advisory x_refsource_confirm
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES
Patch, Vendor Advisory x_refsource_confirm
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24889
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31359
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_6_sr.html
Patch, Vendor Advisory x_refsource_confirm
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES
Patch, Vendor Advisory x_refsource_confirm
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/31525
Patch, Vendor Advisory x_refsource_confirm
http://sourceforge.net/forum/forum.php?forum_id=652721
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/21956
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23647
Scores
EPSS
0.2218
EPSS Percentile
95.8%
Details
Status
published
Products (14)
mediawiki/mediawiki
1.6.0
mediawiki/mediawiki
1.6.1
mediawiki/mediawiki
1.6.2
mediawiki/mediawiki
1.6.3
mediawiki/mediawiki
1.6.4
mediawiki/mediawiki
1.6.5
mediawiki/mediawiki
1.6.5_r14348
mediawiki/mediawiki
1.6.6
mediawiki/mediawiki
1.7.0
mediawiki/mediawiki
1.7.1
... and 4 more
Published
Jan 11, 2007
Tracked Since
Feb 18, 2026