First published: Tue Jun 28 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | <=2010-11-07a | |
DokuWiki | =2005-07-01 | |
DokuWiki | =2005-07-13 | |
DokuWiki | =2005-09-19 | |
DokuWiki | =2005-09-22 | |
DokuWiki | =2006-03-05 | |
DokuWiki | =2006-03-09 | |
DokuWiki | =2006-11-06 | |
DokuWiki | =2007-06-26 | |
DokuWiki | =2008-05-05 | |
DokuWiki | =2009-02-14b | |
DokuWiki | =2009-12-25c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2510 is classified as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2011-2510, upgrade DokuWiki to the version released after May 25, 2011.
CVE-2011-2510 affects multiple versions of DokuWiki prior to 2011-05-25a Rincewind.
Yes, attackers can exploit CVE-2011-2510 remotely to inject arbitrary web scripts or HTML.
CVE-2011-2510 is caused by DokuWiki's RSS embedding feature not properly escaping user-provided links.