CVE-2011-1578
published 2011-04-27CVE-2011-1578: Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.59%
83.7th percentile
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character.
Affected
121 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.15.5-5 (bookworm) | mediawiki 1:1.15.5-5 (bookworm) |
| debian | mediawiki | — | — |
| mediawiki | mediawiki | <= 1.16.3 | — |
| mediawiki | mediawiki | <= 1.16.2 | — |
| mediawiki | mediawiki | <= 1.16.4 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-1578: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Intern...
vendor_debian·2011·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Intern...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-5)
bullseye: resolved (fixed in 1:1.15.5-5)
forky: resolved (fixed in 1:1.15.5-5)
sid: resolved (fixed in 1:1.15.5-5)
trixie: resolved (fixed in 1:1.15.5-5)
Debian
CVE-2011-1587: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Intern...
vendor_debian·2011·CVSS 4.3
CVE-2011-1587 [MEDIUM] CVE-2011-1587: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Intern...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html located before a ? (question mark) in a query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-5)
bullseye: resolved (fixed in 1:1.15.5-5)
forky: resolved (fixed in 1:1.15.5-5)
sid: resolved (fixed in 1:1.15.5-5)
trixie: resolved (fixed in 1:1.15.5-5)
Debian
CVE-2011-1765: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Intern...
vendor_debian·2011·CVSS 4.3
CVE-2011-1765 [MEDIUM] CVE-2011-1765: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Intern...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .shtml at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578 and CVE-2011-1587.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-28vc-7qpm-6gqr: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2011-1587 [MEDIUM] CWE-79 GHSA-28vc-7qpm-6gqr: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html located before a ? (question mark) in a query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578.
GHSA
GHSA-wfr3-766x-cfv9: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2011-1765 [MEDIUM] CWE-79 GHSA-wfr3-766x-cfv9: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .shtml at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578 and CVE-2011-1587.
GHSA
GHSA-84xm-3937-g9jm: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
ghsa_unreviewed·2022-05-13
CVE-2011-1578 [MEDIUM] CWE-79 GHSA-84xm-3937-g9jm: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character.
OSV
CVE-2011-1587: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
osv·2011-04-27·CVSS 4.3
CVE-2011-1587 [MEDIUM] CVE-2011-1587: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html located before a ? (question mark) in a query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578.
OSV
CVE-2011-1578: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
osv·2011-04-27·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578: Cross-site scripting (XSS) vulnerability in MediaWiki before 1
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
Mediawiki 1.16.3 was released [1] to correct three security flaws:
Masato Kinugawa discovered a cross-site scripting (XSS) issue, which
affects Internet Explorer clients only, and only version 6 and
earlier. Web server configuration changes are required to fix this
issue. Upgrading MediaWiki will only be sufficient for people who use
Apache with AllowOverride enabled. (CVE-2011-1578)
Wikipedia user Suffusion of Yellow discovered a CSS validation error
in the wikitext parser. This is an XSS issue for Internet Explorer
clients, and a privacy loss issue for other clients since it allows
the embedding of arbitrary remote images. (CVE-2011-1579)
MediaWiki developer Happy-Melon
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=696360
Please note: this iss
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=696360
Please n
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000096.htmlhttp://openwall.com/lists/oss-security/2011/04/13/15http://secunia.com/advisories/44142http://www.debian.org/security/2011/dsa-2366http://www.securityfocus.com/bid/47354http://www.vupen.com/english/advisories/2011/0978http://www.vupen.com/english/advisories/2011/1100http://www.vupen.com/english/advisories/2011/1151https://bugzilla.redhat.com/show_bug.cgi?id=695577https://bugzilla.redhat.com/show_bug.cgi?id=696360https://bugzilla.wikimedia.org/show_bug.cgi?id=28235https://exchange.xforce.ibmcloud.com/vulnerabilities/66737http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000096.htmlhttp://openwall.com/lists/oss-security/2011/04/13/15http://secunia.com/advisories/44142http://www.debian.org/security/2011/dsa-2366http://www.securityfocus.com/bid/47354http://www.vupen.com/english/advisories/2011/0978http://www.vupen.com/english/advisories/2011/1100http://www.vupen.com/english/advisories/2011/1151https://bugzilla.redhat.com/show_bug.cgi?id=695577https://bugzilla.redhat.com/show_bug.cgi?id=696360https://bugzilla.wikimedia.org/show_bug.cgi?id=28235https://exchange.xforce.ibmcloud.com/vulnerabilities/66737
2011-04-27
Published