Candidate: CVE-2010-1647 PublicDate: 2010-06-08 00:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1647 http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html Description: Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer. Ubuntu-Description: Notes: Bugs: https://bugzilla.wikimedia.org/show_bug.cgi?id=23687 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mediawiki: upstream: http://www.mediawiki.org/wiki/Special:Code/MediaWiki/66990 upstream: http://www.mediawiki.org/wiki/Special:Code/MediaWiki/66992 upstream_mediawiki: released (1.15.4,1.16b3) dapper_mediawiki: ignored (reached end-of-life) hardy_mediawiki: released (1:1.11.2-2ubuntu0.6) jaunty_mediawiki: released (1:1.13.3-1ubuntu2.3) karmic_mediawiki: released (1:1.15.0-1.1ubuntu0.3) lucid_mediawiki: released (1:1.15.1-1ubuntu2.1) devel_mediawiki: released (1:1.15.1-1ubuntu3)