VWE-2010-0075 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2010-0075
This page is a chapter in Info Known Vulnerabilities

This page has been seen 359,884 times.

    • Created by on
      Last updated by on
Common NameLink Recall Vulnerability
VWE-IDVWE-2010-0075
Related ReportNone
SeverityHIGH
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection. Does not affect Lite versions.
DiscoveredSeptember 18, 2010
ResolvedSeptember 30, 2010
Patches Available3.0.4
2.5.7 Patch Level 3
WorkaroundIn Settings > Options > VaultWiki: Server Settings, disable "Enable Link Caching."
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.