CVE-2012-0283
DokuWiki <2012-01-25b - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.
References (7)
Scores
EPSS
0.0052
EPSS Percentile
66.4%
Classification
CWE
CWE-79
Status
published
Affected Products (18)
andreas_gohr/dokuwiki
< 2012-01-25a
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
andreas_gohr/dokuwiki
... and 3 more
Timeline
Published
Jul 13, 2012
Tracked Since
Feb 18, 2026