Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.21.1 | 1.21.1.x |
| mediawiki / mediawiki | 1.20.6 | 1.20.6.x |
| mediawiki / mediawiki | 1.19.7 | 1.19.7.x |