How to Buy
This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.
The remote web server contains an application that is affected by
According to its version number, the instance of MediaWiki running on
the remote host is affected by the following vulnerabilities :
- Escape sequences are not properly sanitized when passed
to the 'Sanitizer::checkCss' class, which allows a
remote attacker to conduct cross-site scripting attacks.
- An input validation error exists in the
'XmlTypeCheck.php' script in uploaded SVG files that
contain external style sheets, which allows a remote
attacker to conduct cross-site scripting attacks.
- Input validation by the checkSvgScriptCallback()
function is bypassed in the 'UploadBase.php' script
when an SVG file with invalid XML is uploaded. This
can result in malicious code execution. (CVE-2013-6453)
- An input validation error exists in the 'Sanitizer.php'
script when input is submitted to the '-o-link'
attribute, which allows cross-site scripting attacks in
Opera 12. (CVE-2013-6454)
- An information disclosure vulnerability exists in the
log API, Enhanced Recent Changes feature, and users'
watchlists that allows deleted log entries to be viewed.
Additionally, the following extensions contain vulnerabilities but
are not enabled or installed by default (unless otherwise noted) :
- The TimedMediaHandler extension is affected by a
cross-site scripting vulnerability due to the lack of
input validation of the 'data-videopayload' attribute
in the 'mw.PopUpThumbVideo.js' script. (CVE-2013-4574)
- The Scribuntu extension is affected by a NULL pointer
dereference and buffer overflow flaw in the
implementation of the 'luasandbox' PHP extension that
can lead to a denial of service or arbitrary code
execution. (CVE-2013-4570, CVE-2013-4571)
- The CentralAuth extension is affected by an information
disclosure vulnerability due to the insertion of a
username into the page's DOM. (CVE-2013-6455)
- The Semantic Forms extension is affected by a cross-site
request forgery (XSRF) vulnerability due to the lack of
token validation in the 'Special:CreateCategory' page.
Note that Nessus has not tested for these issues but has instead
relied on the application's self-reported version number.
See also :
Upgrade to MediaWiki version 1.19.10 / 1.21.4 / 1.22.1 or later.
Risk factor :
Medium / CVSS Base Score : 6.8
CVSS Temporal Score : 5.9
Public Exploit Available : true
Family: CGI abuses
Nessus Plugin ID: 72370 ()
Bugtraq ID: 649666500367522
CVE ID: CVE-2013-4570CVE-2013-4571CVE-2013-4574CVE-2013-6451CVE-2013-6452CVE-2013-6453CVE-2013-6454CVE-2013-6455CVE-2013-6472CVE-2014-3454
Nessus Professional: Scan unlimited IPs, run compliance checks & moreNessus Cloud: The power of Nessus for teams – from the cloud
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.