← Back

CVE-2005-3167

nvd nist
Published: Oct 6, 2005Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

Affected (15)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Version 1.4.10
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4_beta1
Version 1.4_beta2
Version 1.4_beta3
Version 1.4_beta4
Version 1.4_beta5
Version 1.4_beta6

References (8)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.