|
271481
|
- |
|
mediawiki
|
checkuser
|
Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive use…
|
CWE-352
Origin Validation Error
|
CVE-2015-2940
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271482
|
- |
|
mediawiki
|
scribunto
|
Cross-site scripting (XSS) vulnerability in the Scribunto extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a function name, which is not properly handled in …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2939
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271483
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2938
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271484
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attackers to cause a denial of service ("quadratic blowup" and memory consumption) v…
|
CWE-399
Resource Management Errors
|
CVE-2015-2937
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271485
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
|
CWE-399
Resource Management Errors
|
CVE-2015-2936
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271486
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style el…
|
CWE-200
Information Exposure
|
CVE-2015-2935
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271487
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2934
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271488
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2933
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271489
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2932
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271490
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2931
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|