VWE-2010-0102 Printable Version
This page is a chapter in Info Known Vulnerabilities
This page has been seen 4,233 times.
-
-
Created by on
-
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name Template Inheritance Vulnerability VWE-ID VWE-2010-0102 Related Report None Severity HIGH Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description HTML/Javascript injection. HTML can be parsed in deeply nested templates even though the wiki forum containing the template does not allow HTML.
Discovered July 27, 2010 Resolved July 28, 2010 Patches Available 3.0.2
Notes
Even though this issue also affected the 2.x series, it was not addressed until a later patch, due to filename changes and a misconception that nested templates were only recently added in the 3.x series. Thus, there are two vulnerabilities with the same AKA.