CVE-2009-0737

Publication date 25 February 2009

Last updated 24 July 2024


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Status

Package Ubuntu Release Status
mediawiki 9.10 karmic
Fixed 1:1.13.3-1ubuntu2
9.04 jaunty
Fixed 1:1.13.3-1ubuntu2
8.10 intrepid
Fixed 1:1.12.0-2ubuntu0.3
8.04 LTS hardy
Fixed 1:1.11.2-2ubuntu0.3
7.10 gutsy Ignored end of life, was needs-triage
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities