← Back

CVE-2005-4501

nvd nist
Published: Dec 22, 2005Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

Affected (45)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
45 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Up to 1.5.3
Version 1.1.0
Version 1.2.0
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.3.0
Version 1.3.10
Version 1.3.11
Version 1.3.12
Version 1.3.13
Version 1.3.14
Version 1.3.15
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.5
Version 1.3.6
Version 1.3.7
Version 1.3.8
Version 1.3.9
Version 1.3
Version 1.4.10
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4_beta1
Version 1.4_beta2
Version 1.4_beta3
Version 1.4_beta4
Version 1.4_beta5
Version 1.4_beta6
Version 1.5_alpha1
Version 1.5_alpha2
Version 1.5_beta1
Version 1.5_beta2

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.