First published: Fri Jul 13 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | <=2012-01-25a | |
DokuWiki | =2005-07-01 | |
DokuWiki | =2005-09-19 | |
DokuWiki | =2005-09-22 | |
DokuWiki | =2006-03-05 | |
DokuWiki | =2006-03-09 | |
DokuWiki | =2006-11-06 | |
DokuWiki | =2007-06-26 | |
DokuWiki | =2007-07-13 | |
DokuWiki | =2008-05-05 | |
DokuWiki | =2009-02-14b | |
DokuWiki | =2009-12-25c | |
DokuWiki | =2010-11-07a | |
DokuWiki | =2011-05-25 | |
DokuWiki | =2011-05-25a | |
DokuWiki | =2011-05-25c | |
DokuWiki | =2012-01-25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0283 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2012-0283, upgrade DokuWiki to version 2012-01-25b or later.
CVE-2012-0283 affects all DokuWiki versions prior to 2012-01-25b.
CVE-2012-0283 allows remote attackers to inject arbitrary web scripts or HTML, which can compromise user data and session security.
Yes, CVE-2012-0283 specifically impacts the ns parameter in a medialist action to lib/exe/ajax.php.