CVE-2008-0460
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 th
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8.
and (2) the BotQuery extension for MediaWiki 1.7 and earlier.
when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MEDIUM · CVSS 4.3
EPSS 0.1566
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 5% of all CVEs by exploitation likelihood
Sigma rules2
YARA rules0