CVE-2012-0220
- EPSS 0.47%
- Veröffentlicht 29.05.2012 20:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.
CVE-2011-1401
- EPSS 0.39%
- Veröffentlicht 11.04.2011 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading ...
CVE-2010-1195
- EPSS 0.32%
- Veröffentlicht 31.03.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.
- EPSS 0.53%
- Veröffentlicht 31.08.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.
CVE-2008-0169
- EPSS 0.47%
- Veröffentlicht 03.06.2008 15:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an...
CVE-2008-0165
- EPSS 0.24%
- Veröffentlicht 21.04.2008 13:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.
CVE-2008-0808
- EPSS 0.48%
- Veröffentlicht 19.02.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.
CVE-2008-0809
- EPSS 0.33%
- Veröffentlicht 19.02.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents.