CVE

Id
14371  
CVE No.
CVE-2005-3165  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.  
Phase
Assigned (20051006)  
Votes
None (candidate not yet proposed)  
Comments