Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3966
Description:Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid username.
Test IDs: 1.3.6.1.4.1.25623.1.0.702957   1.3.6.1.4.1.25623.1.1.10.2014.0253  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3966
BugTraq ID: 67787
http://www.securityfocus.com/bid/67787
Debian Security Information: DSA-2957 (Google Search)
http://www.debian.org/security/2014/dsa-2957
http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-May/000151.html
http://www.openwall.com/lists/oss-security/2014/06/04/15
http://www.securitytracker.com/id/1030364
http://secunia.com/advisories/58834
http://secunia.com/advisories/58896




© 1998-2025 E-Soft Inc. All rights reserved.