Details
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page.Novell Bugzilla entry: 443303,459058 SUSE Security Advisories:
- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
- SUSE-SR:2009:004 , published Tue, 17 Feb 2009 10:00:00 +0000
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 10.3 |
| ZYPP Patch Nr: 5987 SAT Patch Nr: 506 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5987 SAT Patch Nr: 506 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5987 SAT Patch Nr: 506 |