The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2010-0094 Related Report None Severity MEDIUM Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description HTML/Javascript injection. A malicious user can craft a malicious query string that, when present in the server's REQUEST_URI, can be included in an article's table of contents links unencoded.
Discovered May 2010 Resolved May 15, 2010 Patches Available 3.0.0 RC 3 Notes
When the patch was originally released, it was believed that the issue only affected VaultWiki 3.x versions, because the affected code appeared to be sufficiently different from 2.x versions. However, the underlying logic, although coded differently, was still present in 2.x, so it remained unpatched until the end-of-life of that series.
This page has been seen 4,124 times.
-
-
Created by on
-