VWE-2010-0074-1 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2010-0074-1
This page is a chapter in Info Known Vulnerabilities

This page has been seen 469,084 times.

    • Created by on
      Last updated by on
Common NameTemplate Inheritance Vulnerability
VWE-IDVWE-2010-0074-1
Related ReportNone
SeverityHIGH
Exploit DifficultyNORMAL
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection. Does not affect Lite versions.
DiscoveredSeptember 22, 2010
ResolvedSeptember 30, 2010
Patches Available2.5.7 Patch level 3
WorkaroundUpdate all wiki forums so that none allow HTML. Alternatively, disable the template BB-Code (default: TEMPLATE) via the Wiki Code Manager.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.