CVE-2011-1579
published 2011-04-27CVE-2011-1579: The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token…
PriorityP424medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.92%
77.7th percentile
The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments.
Affected
116 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.15.5-5 (bookworm) | mediawiki 1:1.15.5-5 (bookworm) |
| mediawiki | mediawiki | <= 1.16.2 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwjq-pqc6-6rcp: The checkCss function in includes/Sanitizer
ghsa_unreviewed·2022-05-17
CVE-2011-1579 [MEDIUM] CWE-20 GHSA-rwjq-pqc6-6rcp: The checkCss function in includes/Sanitizer
The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments.
OSV
CVE-2011-1579: The checkCss function in includes/Sanitizer
osv·2011-04-27·CVSS 5.8
CVE-2011-1579 [MEDIUM] CVE-2011-1579: The checkCss function in includes/Sanitizer
The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments.
Debian
CVE-2011-1579: mediawiki - The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaW...
vendor_debian·2011·CVSS 5.8
CVE-2011-1579 [MEDIUM] CVE-2011-1579: mediawiki - The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaW...
The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-5)
bullseye: resolved (fixed in 1:1.15.5-5)
forky: resolved (fixed in 1:1.15.5-5)
sid: resolved (fixed in 1:1.15.5-5)
trixie: resolved (fixed in 1:1.15.5-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1587 mediawiki: multiple vulnerabilities fixed in 1.16.3, 1.16.4
Mediawiki 1.16.3 was released [1] to correct three security flaws:
Masato Kinugawa discovered a cross-site scripting (XSS) issue, which
affects Internet Explorer clients only, and only version 6 and
earlier. Web server configuration changes are required to fix this
issue. Upgrading MediaWiki will only be sufficient for people who use
Apache with AllowOverride enabled. (CVE-2011-1578)
Wikipedia user Suffusion of Yellow discovered a CSS validation error
in the wikitext parser. This is an XSS issue for Internet Explorer
clients, and a privacy loss issue for other clients since it allows
the embedding of arbitrary remote images. (CVE-2011-1579)
MediaWiki developer Happy-Melon
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 CVE-2011-1765 mediawiki116 various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=696360
Please note: this iss
Bugzilla
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
bugzilla·2011-04-13·CVSS 4.3
CVE-2011-1578 [MEDIUM] CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
CVE-2011-1578 CVE-2011-1579 CVE-2011-1580 mediawiki: multiple vulnerabilities fixed in 1.16.3 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=696360
Please n
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000096.htmlhttp://openwall.com/lists/oss-security/2011/04/13/15http://secunia.com/advisories/44142http://www.debian.org/security/2011/dsa-2366http://www.mediawiki.org/wiki/Special:Code/MediaWiki/85856http://www.securityfocus.com/bid/47354http://www.vupen.com/english/advisories/2011/0978http://www.vupen.com/english/advisories/2011/1100http://www.vupen.com/english/advisories/2011/1151https://bugzilla.redhat.com/show_bug.cgi?id=695577https://bugzilla.redhat.com/show_bug.cgi?id=696360https://bugzilla.wikimedia.org/show_bug.cgi?id=28450https://exchange.xforce.ibmcloud.com/vulnerabilities/66738http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000096.htmlhttp://openwall.com/lists/oss-security/2011/04/13/15http://secunia.com/advisories/44142http://www.debian.org/security/2011/dsa-2366http://www.mediawiki.org/wiki/Special:Code/MediaWiki/85856http://www.securityfocus.com/bid/47354http://www.vupen.com/english/advisories/2011/0978http://www.vupen.com/english/advisories/2011/1100http://www.vupen.com/english/advisories/2011/1151https://bugzilla.redhat.com/show_bug.cgi?id=695577https://bugzilla.redhat.com/show_bug.cgi?id=696360https://bugzilla.wikimedia.org/show_bug.cgi?id=28450https://exchange.xforce.ibmcloud.com/vulnerabilities/66738
2011-04-27
Published