
CVE-2014-9276 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9276
04 Jan 2015 — Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgRawHTML is set to true, allows remote attackers to hijack the authentication of users with edit permissions for requests that cross-site scripting (XSS) attacks via the wpInput parameter, which is not properly handled in the preview. Vulnerabilidad de CSRF en la página Special:ExpandedTemplates en MediaWiki anterior a 1.19.... • http://securitytracker.com/id?1031301 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-9507 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9507
04 Jan 2015 — MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks by setting the content model for a revision to JS. MediaWiki versiones 1.21.x, versiones 1.22.x anteriores a 1.22.14, y versiones 1.23.x anteriores a 1.23.7, cuando $wgContentHandlerUseDB está habilitado, permite a los atacantes remotos conducir ataques de tipo cross-site-scripting (XSS) mediante el ajuste del modelo de contenido par... • https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9277 – Debian Security Advisory 3100-1
https://notcve.org/view.php?id=CVE-2014-9277
13 Dec 2014 — The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing

CVE-2014-7295 – Mandriva Linux Security Advisory 2014-198
https://notcve.org/view.php?id=CVE-2014-7295
06 Oct 2014 — The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css. Las páginas (1) Special:Preferences y (2) Special:UserLogin en MediaWiki anterior a 1.19.20, 1.22.x anterior a 1.22.12 y 1.23.x anterior a 1.23.5 permite a usuarios remotos autenticados realizar ... • http://seclists.org/oss-sec/2014/q4/67 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-7199 – Mandriva Linux Security Advisory 2014-198
https://notcve.org/view.php?id=CVE-2014-7199
30 Sep 2014 — Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file. Vulnerabilidad de XSS en MediaWiki anterior a 1.19.19, 1.22.x anterior a 1.22.11, y 1.23.x anterior a 1.23.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un fichero SVG manipulado. MediaWiki before 1.23.4 is vulnerable to cross-site scripting due to JavaScr... • http://secunia.com/advisories/61666 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-5241 – Debian Security Advisory 3011-1
https://notcve.org/view.php?id=CVE-2014-5241
22 Aug 2014 — The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set. El endpoint JSONP en includes/api/ApiFormatJson.php en MediaWi... • http://advisories.mageia.org/MGASA-2014-0309.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-5242 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-5242
22 Aug 2014 — Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving the multipageimagenavbox class in conjunction with an action=raw value. Vulnerabilidad de XSS en mediawiki.page.image.pagination.js en MediaWiki 1.22.x anterior a 1.22.9 y 1.23.x anterior a 1.23.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través ... • http://advisories.mageia.org/MGASA-2014-0309.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-5243 – Debian Security Advisory 3011-1
https://notcve.org/view.php?id=CVE-2014-5243
22 Aug 2014 — MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. MediaWiki anterior a 1.19.18, 1.20.x hasta 1.22.x anterior a 1.22.9, y 1.23.x anterior a 1.23.2 no aplica un mecanismo de protección IFRAME para páginas transcluidas, lo que facilita a atacantes remotos realizar ataques de clickjacking a través de un sit... • http://advisories.mageia.org/MGASA-2014-0309.html • CWE-20: Improper Input Validation •

CVE-2014-3966 – Debian Security Advisory 2957-1
https://notcve.org/view.php?id=CVE-2014-3966
06 Jun 2014 — Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username. Vulnerabilidad de XSS en Special:PasswordReset in MediaWiki anterior a 1.19.16, 1.21.x anterior a 1.21.10 y 1.22.x anterior a 1.22.7, cuando wgRawHtml está habilitado, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a ... • http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-May/000151.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-5391
https://notcve.org/view.php?id=CVE-2012-5391
02 Jun 2014 — Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id. Vulnerabilidad de fijación de sesión en Special:UserLogin en MediaWiki anterior a 1.18.6, 1.19.x anterior a 1.19.3 y 1.20.x anterior a 1.20.1 permite a atacantes remotos secuestrar sesiones web a través de session_id. • http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098975.html •