Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "A3EAF847-B64C-4C12-8BF2-631F61B0618E", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "09EF3827-9C87-4043-B10A-1D6AFCB64F57", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "08B1EDE8-940E-47C1-9CDA-C6BBE1BB9A11", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "A4554900-E09D-4D9D-99D4-FE5FDB3CDE78", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*", "matchCriteriaId": "93EB0312-A147-4307-9491-46AEC2EC727C", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*", "matchCriteriaId": "48929086-E08E-472D-A503-4CA803A840D5", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*", "matchCriteriaId": "A98675FD-C9EA-49AB-BA9F-2CF5898203C7", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.7:*:*:*:*:*:*:*", "matchCriteriaId": "EB9B4718-DF85-4E77-B720-0EC3E0D318BB", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.8:*:*:*:*:*:*:*", "matchCriteriaId": "132A745B-0A1B-4186-8BE2-88C24FF4A455", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.9:*:*:*:*:*:*:*", "matchCriteriaId": "E710375D-F5B3-4998-AA7F-F931022CF6F4", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.10:*:*:*:*:*:*:*", "matchCriteriaId": "3130C952-83B3-4755-99D7-D25C1447670E", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.6.11:*:*:*:*:*:*:*", "matchCriteriaId": "9842D148-50D2-4A52-A3E1-529670A25EBD", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*", "matchCriteriaId": "746023B5-2472-4FC9-BEDF-FE6A321F12B9", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*", "matchCriteriaId": "0D18C85B-E82B-46AE-959E-3FD32DB6F294", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*", "matchCriteriaId": "66714539-F1E1-4C16-AA12-059EEB1B9DF6", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*", "matchCriteriaId": "A80044C9-9F76-468E-84F7-D7D529004AE6", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*", "matchCriteriaId": "C7CD7F5A-F4E4-45B6-9179-BD1BCD75D297", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*", "matchCriteriaId": "79CDE6D3-A26D-4ECD-B949-B9DDB53F67C3", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*", "matchCriteriaId": "D3CC82BE-8DEA-47D7-B6B7-2FFDFB728ADE", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*", "matchCriteriaId": "AFD79470-63A7-438B-A3BE-CABDAD7F848C", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*", "matchCriteriaId": "A26F4C94-E3A5-456E-8E5E-36BA67DD4BD5", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*", "matchCriteriaId": "C7C6D23B-B5C1-4F10-9F62-E81F639FF40F", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.3:*:*:*:*:*:*:*", "matchCriteriaId": "13FA8F3C-2B6C-42FB-A6CE-EC2D8614E43D", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados - XSS - en el instalador basado en web (config/index.php) en MediaWiki v1.6 anteriores a v1.6.12, v1.12 anteriores a v1.12.4, y v1.13 anteriores a v1.13.4, cuando el instalador est\u00e1 activo, permite a los atacantes remotos inyectar arbitrariamente una secuencia de comandos web o HTML a trav\u00e9s de vectores no especificados."}], "id": "CVE-2009-0737", "lastModified": "2025-04-09T00:30:58.490", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 4.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2009-02-25T20:30:02.483", "references": [{"source": "cve@mitre.org", "tags": ["Patch"], "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2009-February/000083.html"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/33881"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTES"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTES"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTES"}, {"source": "cve@mitre.org", "url": "http://www.debian.org/security/2009/dsa-1901"}, {"source": "cve@mitre.org", "tags": ["Patch"], "url": "http://www.securityfocus.com/bid/33681"}, {"source": "cve@mitre.org", "tags": ["Patch", "Vendor Advisory"], "url": "http://www.vupen.com/english/advisories/2009/0368"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch"], "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2009-February/000083.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/33881"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTES"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTES"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTES"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2009/dsa-1901"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch"], "url": "http://www.securityfocus.com/bid/33681"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Vendor Advisory"], "url": "http://www.vupen.com/english/advisories/2009/0368"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}