← Back

CVE-2012-0283

nvd nist
Published: Jul 13, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.

Affected (17)

1 product
Dokuwiki
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Andreas Gohr
Up to 2012-01-25a
Version 2005-07-01
Version 2005-09-19
Version 2005-09-22
Version 2006-03-05
Version 2006-03-09
Version 2006-11-06
Version 2007-06-26
Version 2007-07-13
Version 2008-05-05
Version 2009-02-14b
Version 2009-12-25c
Version 2010-11-07a
Version 2011-05-25
Version 2011-05-25a
Version 2011-05-25c
Version 2012-01-25

References (14)

Source: PSIRT-CNA@flexerasoftware.com
Vendor Advisory
Source: PSIRT-CNA@flexerasoftware.com
Vendor Advisory
Source: PSIRT-CNA@flexerasoftware.com
Source: PSIRT-CNA@flexerasoftware.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.