CVE-2008-0460
EPSS 14.6%
描述
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
如何修補 CVE-2008-0460
要修補 CVE-2008-0460,請將受影響套件升級到下列已修補版本。
- Debian/mediawiki—升級至 1:1.11.1-1 或更新版本
CVE-2008-0460 正在被利用嗎?
中等 — EPSS 為 14.6%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1:1.11.1-1