Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.
Software | From | Fixed in |
---|---|---|
andreas_gohr / dokuwiki | 2006-11-06 | 2006-11-06.x |
andreas_gohr / dokuwiki | 2006-03-05 | 2006-03-05.x |
andreas_gohr / dokuwiki | 2011-05-25 | 2011-05-25.x |
andreas_gohr / dokuwiki | 2011-05-25c | 2011-05-25c.x |
andreas_gohr / dokuwiki | 2005-09-22 | 2005-09-22.x |
andreas_gohr / dokuwiki | 2005-07-01 | 2005-07-01.x |
andreas_gohr / dokuwiki | 2010-11-07a | 2010-11-07a.x |
andreas_gohr / dokuwiki | 2009-12-25c | 2009-12-25c.x |
andreas_gohr / dokuwiki | 2009-02-14b | 2009-02-14b.x |
andreas_gohr / dokuwiki | 2012-01-25 | 2012-01-25.x |
andreas_gohr / dokuwiki | 2005-09-19 | 2005-09-19.x |
andreas_gohr / dokuwiki | 2011-05-25a | 2011-05-25a.x |
andreas_gohr / dokuwiki | 2006-03-09 | 2006-03-09.x |
andreas_gohr / dokuwiki | 2008-05-05 | 2008-05-05.x |
andreas_gohr / dokuwiki | - | 2012-01-25a.x |
andreas_gohr / dokuwiki | 2007-06-26 | 2007-06-26.x |
andreas_gohr / dokuwiki | 2007-07-13 | 2007-07-13.x |