MediaWiki.Parser.Script.Insertion.XSS

description-logoDescription

This indicates an attack attempt against a cross-site scripting (XSS) vulnerability in MediaWiki.
The vulnerability exists in includes/Sanitizer.php in the variable handler. It is caused by the application's inability to properly sanitize user-supplied input. It may allow a remote attacker to execute arbitrary script.

affected-products-logoAffected Products

MediaWiki versions prior to 1.6.6

Impact logoImpact

Arbitrary Javascript Injection.

recomended-action-logoRecommended Actions

Upgrade to MediaWiki version 1.6.6:
http://www.mediawiki.org/wiki/Download

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)