CVE-2012-0220: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0220?
CVE-2012-0220 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-0220?
To fix CVE-2012-0220, upgrade to ikiwiki version 3.20120516 or later to ensure protection against the identified vulnerabilities.
What types of attacks can CVE-2012-0220 enable?
CVE-2012-0220 can enable remote attackers to inject arbitrary web script or HTML into affected sites via the author or authorurl meta tags.
Which versions of ikiwiki are affected by CVE-2012-0220?
CVE-2012-0220 affects ikiwiki versions prior to 3.20120516, including all versions from 1.0 through 3.20120419.
Are there known exploits for CVE-2012-0220?
There are no public proof-of-concept exploits for CVE-2012-0220, but the potential for exploitation exists given the nature of the vulnerabilities.