← Back

CVE-2008-0460

nvd nist
Published: Jan 25, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected (18)

2 products
Mediawiki
Mediawiki Botquery Ext
1 product
Internet Explorer
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Version 1.10.0
Version 1.10.1
Version 1.10.2
Version 1.11.0rc1
Version 1.11
Version 1.8.0
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.9.0
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.7.0
All versions
All versions

Timeline

No history available yet.