CVE
- Id
- 14371
- CVE No.
- CVE-2005-3165
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.
- Phase
- Assigned (20051006)
- Votes
- None (candidate not yet proposed)
- Comments