CVE-2012-0283: XSS
Published Jul 13, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the tplmediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.
Affected Software
17 affected components
Andreas Gohr Dokuwiki<=2012-01-25a
Andreas Gohr Dokuwiki=2005-07-01
Andreas Gohr Dokuwiki=2005-09-19
Andreas Gohr Dokuwiki=2005-09-22
Andreas Gohr Dokuwiki=2006-03-05
Andreas Gohr Dokuwiki=2006-03-09
Andreas Gohr Dokuwiki=2006-11-06
Andreas Gohr Dokuwiki=2007-06-26
Andreas Gohr Dokuwiki=2007-07-13
Andreas Gohr Dokuwiki=2008-05-05
Andreas Gohr Dokuwiki=2009-02-14b
Andreas Gohr Dokuwiki=2009-12-25c
Andreas Gohr Dokuwiki=2010-11-07a
Andreas Gohr Dokuwiki=2011-05-25
Andreas Gohr Dokuwiki=2011-05-25a
Andreas Gohr Dokuwiki=2011-05-25c
Andreas Gohr Dokuwiki=2012-01-25
Event History
Jul 13, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0283?
CVE-2012-0283 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-0283?
To fix CVE-2012-0283, upgrade DokuWiki to version 2012-01-25b or later.
3
What versions of DokuWiki are affected by CVE-2012-0283?
CVE-2012-0283 affects all DokuWiki versions prior to 2012-01-25b.
4
What is the impact of CVE-2012-0283?
CVE-2012-0283 allows remote attackers to inject arbitrary web scripts or HTML, which can compromise user data and session security.
5
Is CVE-2012-0283 specific to certain actions in DokuWiki?
Yes, CVE-2012-0283 specifically impacts the ns parameter in a medialist action to lib/exe/ajax.php.