CVE-2005-4501: XSS
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4501?
CVE-2005-4501 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2005-4501?
To mitigate CVE-2005-4501, upgrade your MediaWiki installation to version 1.5.4 or later.
Who is affected by CVE-2005-4501?
CVE-2005-4501 affects MediaWiki versions prior to 1.5.4, including several versions as low as 1.1.0.
What type of vulnerability is CVE-2005-4501?
CVE-2005-4501 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2005-4501 be exploited remotely?
Yes, CVE-2005-4501 can be exploited remotely by attackers, allowing them to execute JavaScript code in the context of a victim's browser.