CVE-2013-6047
https://notcve.org/view.php?id=CVE-2013-6047
Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en la interfaz de creación de sitios en ikiwiki-hosting anterior a 0.20131025 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través de vectores no especificados. • http://osvdb.org/99012 http://packages.qa.debian.org/i/ikiwiki-hosting/news/20131025T224825Z.html http://seclists.org/oss-sec/2013/q4/180 https://exchange.xforce.ibmcloud.com/vulnerabilities/88334 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-0220
https://notcve.org/view.php?id=CVE-2012-0220
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el plugin en Plugin/meta.pm en ikiwiki anterior a v3.20120516 , permite a atacantes remotos inyectar secuencias de comandos web o HTML a través (1) del parámetro author o (2) de la meta etiqueta authorurl. • http://ikiwiki.info/news/version_3.20120516 http://osvdb.org/81995 http://secunia.com/advisories/49199 http://secunia.com/advisories/49232 http://source.ikiwiki.branchable.com/?p=source.git%3Ba=commitdiff%3Bh=fbfcea89f8e06426c73ab8ea369ca4cdc566db6f http://www.debian.org/security/2012/dsa-2474 http://www.securityfocus.com/bid/53599 https://exchange.xforce.ibmcloud.com/vulnerabilities/75702 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2011-1401
https://notcve.org/view.php?id=CVE-2011-1401
ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet. ikiwiki anterior a v3.20110328 no establece si el plugin htmlscrubber está habilitado durante el proceso de la directiva "meta stylesheet", lo que permite a usuarios autenticados de forma remota conducir un ataque de vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) a través de hojas de estilo en cascada (CSS) manipuladas en (1) la hoja de estilo por defecto o (2) en una hoja de estilo alternativa. • http://ikiwiki.info/security/#index39h2 http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058403.html http://secunia.com/advisories/44079 http://secunia.com/advisories/44137 http://www.debian.org/security/2011/dsa-2214 http://www.securityfocus.com/bid/47285 http://www.vupen.com/english/advisories/2011/0907 http://www.vupen.com/english/advisories/2011/1005 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2010-1195
https://notcve.org/view.php?id=CVE-2010-1195
Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el componente htmlscrubber en ikiwiki 2.x en versiones anteriores a la 2.53.5 y 3.x en versiones anteriores a la 3.20100312 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante una URI data:image/svg+xml manipulada. • http://ikiwiki.info/security/#index36h2 http://secunia.com/advisories/38983 http://secunia.com/advisories/39048 http://www.debian.org/security/2010/dsa-2020 http://www.vupen.com/english/advisories/2010/0662 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2009-2944
https://notcve.org/view.php?id=CVE-2009-2944
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands. Vulnerabilidad de lista negra incompleta en el plugin teximg en ikiwiki anterior a v3.1415926 y v2.x anterior a v2.53.4, permite a atacantes dependientes de contexto leer archivos de su elección a través de comando TeX manipulados. • http://ikiwiki.info/security/#index35h2 http://osvdb.org/57575 http://secunia.com/advisories/36516 http://secunia.com/advisories/36539 http://www.debian.org/security/2009/dsa-1875 http://www.securityfocus.com/bid/36181 http://www.vupen.com/english/advisories/2009/2475 https://exchange.xforce.ibmcloud.com/vulnerabilities/52922 •