CVE-2010-1647

Mediawiki - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.

Scores

EPSS 0.0025
EPSS Percentile 47.9%

Classification

CWE
CWE-79
Status published

Affected Products (9)

mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
n/a/n/a

Timeline

Published Jun 08, 2010
Tracked Since Feb 18, 2026