Lucene search

K
cve[email protected]CVE-2012-0283
HistoryJul 13, 2012 - 9:55 p.m.

CVE-2012-0283

2012-07-1321:55:02
CWE-79
web.nvd.nist.gov
24
cve-2012-0283
cross-site scripting
xss
dokuwiki
tpl_mediafilelist
template.php
web security
vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.2%

Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.

Affected configurations

NVD
Node
andreas_gohrdokuwikiRange2012-01-25a
OR
andreas_gohrdokuwikiMatch2005-07-01
OR
andreas_gohrdokuwikiMatch2005-09-19
OR
andreas_gohrdokuwikiMatch2005-09-22
OR
andreas_gohrdokuwikiMatch2006-03-05
OR
andreas_gohrdokuwikiMatch2006-03-09
OR
andreas_gohrdokuwikiMatch2006-11-06
OR
andreas_gohrdokuwikiMatch2007-06-26
OR
andreas_gohrdokuwikiMatch2007-07-13
OR
andreas_gohrdokuwikiMatch2008-05-05
OR
andreas_gohrdokuwikiMatch2009-02-14b
OR
andreas_gohrdokuwikiMatch2009-12-25c
OR
andreas_gohrdokuwikiMatch2010-11-07a
OR
andreas_gohrdokuwikiMatch2011-05-25
OR
andreas_gohrdokuwikiMatch2011-05-25a
OR
andreas_gohrdokuwikiMatch2011-05-25c
OR
andreas_gohrdokuwikiMatch2012-01-25

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.2%