MediaWiki: Cross-site scripting vulnerability MediaWiki is vulnerable to a cross-site scripting attack that could allow arbitrary JavaScript code execution. mediawiki 2005-07-20 2005-08-11 99132 remote 1.4.6 1.4.6

MediaWiki is a collaborative editing software, used by big projects like Wikipedia.

MediaWiki fails to escape a parameter in the page move template correctly.

By enticing a user to visit a specially crafted URL, a remote attacker could exploit this vulnerability to inject malicious JavaScript code that will be executed in a user's browser session in the context of the vulnerable site.

There is no known workaround at this time.

All MediaWiki users should upgrade to the latest available version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.4.7"
CAN-2005-2396 MediaWiki Release Notes koon koon DerCorny