CVE-2008-4408: XSS
Published Oct 3, 2008
·Updated
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via the useskin parameter to an unspecified component.
Affected Software
2 affected components
MediaWiki MediaWiki=1.12.0
MediaWiki MediaWiki=1.13.1
Event History
Oct 3, 2008
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4408?
The severity of CVE-2008-4408 is considered moderate due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-4408?
To fix CVE-2008-4408, upgrade MediaWiki to version 1.13.2 or later.
3
What versions of MediaWiki are affected by CVE-2008-4408?
CVE-2008-4408 affects MediaWiki versions 1.12.0 and 1.13.1.
4
Can CVE-2008-4408 be exploited remotely?
Yes, CVE-2008-4408 can be exploited remotely by attackers through the useskin parameter.
5
What is the nature of the vulnerability in CVE-2008-4408?
CVE-2008-4408 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.