|
212381
|
- |
|
widgets_project
|
widgets
|
Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6737
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212382
|
- |
|
quiz_project
|
quiz
|
The Quiz extension for MediaWiki allows remote attackers to cause a denial of service via regex metacharacters in a regular expression.
|
CWE-17
Code
|
CVE-2015-6736
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212383
|
- |
|
timedmediahandler_project
|
timedmediahandler
|
The reset functionality in the TimedMediaHandler extension for MediaWiki does not create a new transcode, which allows remote attackers to cause a denial of service (transcode deletion) by resetting …
|
CWE-17
Code
|
CVE-2015-6735
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212384
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6734
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212385
|
- |
|
mediawiki
|
mediawiki
|
GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to cause a denial of service (resource cons…
|
CWE-399
Resource Management Errors
|
CVE-2015-6733
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212386
|
- |
|
semanticforms_project
|
semanticforms
|
Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) wpSummary parameter to Speci…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6732
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212387
|
- |
|
semanticforms_project
|
semanticforms
|
Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via a (1) section_*, (2) template_*, (3)…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6731
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212388
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6730
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212389
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6729
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212390
|
- |
|
mediawiki
|
mediawiki
|
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to…
|
CWE-352
Origin Validation Error
|
CVE-2015-6728
|
2024-11-21 11:35 |
2015-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|