MidnightBSD

Advisories for pmwiki

CVE-2005-3849 MEDIUM

Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.0.5
pmwiki pmwiki 2.0.0
pmwiki pmwiki 2.0.10
pmwiki pmwiki *
pmwiki pmwiki 2.0.11
pmwiki pmwiki 2.0.8
pmwiki pmwiki 2.0.9
pmwiki pmwiki 2.0.4
pmwiki pmwiki 2.0.1
pmwiki pmwiki 2.0.3
pmwiki pmwiki 2.0.2
pmwiki pmwiki 2.0.6
pmwiki pmwiki 2.0.7
CVE-2006-0479 MEDIUM

pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.1_beta_20
CVE-2006-2840 MEDIUM

Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.0.5
pmwiki pmwiki 2.1.2
pmwiki pmwiki 2.0.0
pmwiki pmwiki 2.1.5
pmwiki pmwiki 2.0.10
pmwiki pmwiki *
pmwiki pmwiki 2.0.11
pmwiki pmwiki 2.1.0
pmwiki pmwiki 2.1.3
pmwiki pmwiki 2.0.8
pmwiki pmwiki 2.1.1
pmwiki pmwiki 2.1.4
pmwiki pmwiki 2.0.9
pmwiki pmwiki 2.0.4
pmwiki pmwiki 2.0.1
pmwiki pmwiki 2.0.12
pmwiki pmwiki 2.0.3
pmwiki pmwiki 2.0.2
pmwiki pmwiki 2.0.13
pmwiki pmwiki 2.0.6
pmwiki pmwiki 2.0.7
CVE-2010-1481 LOW

Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.2.15
CVE-2010-4748 MEDIUM

Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.2.20
CVE-2011-4453 HIGH

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
pmwiki pmwiki 2.1.24
pmwiki pmwiki 2.2.34
pmwiki pmwiki 2.2.19
pmwiki pmwiki 2.1.8
pmwiki pmwiki 2.2.15
pmwiki pmwiki 2.2.6
pmwiki pmwiki 2.2.27
pmwiki pmwiki 2.2.0
pmwiki pmwiki 2.2.7
pmwiki pmwiki 2.1.6
pmwiki pmwiki 2.2.11
pmwiki pmwiki 2.0.11
pmwiki pmwiki 2.1.0
pmwiki pmwiki 2.2.30
pmwiki pmwiki 2.1.11
pmwiki pmwiki 2.1.19
pmwiki pmwiki 2.2.4
pmwiki pmwiki 2.2.22
pmwiki pmwiki 2.1.21
pmwiki pmwiki 2.2.26
pmwiki pmwiki 2.2.5
pmwiki pmwiki 2.1.17
pmwiki pmwiki 2.1.4
pmwiki pmwiki 2.1.25
pmwiki pmwiki 2.2.29
pmwiki pmwiki 2.2.12
pmwiki pmwiki 2.0.3
pmwiki pmwiki 2.0.2
pmwiki pmwiki 2.2.17
pmwiki pmwiki 2.0.5
pmwiki pmwiki 2.2.13
pmwiki pmwiki 2.0.0
pmwiki pmwiki 2.1.20
pmwiki pmwiki 2.2.33
pmwiki pmwiki 2.1.18
pmwiki pmwiki 2.1.13
pmwiki pmwiki 2.1.15
pmwiki pmwiki 2.2.25
pmwiki pmwiki 2.2.8
pmwiki pmwiki 2.2.21
pmwiki pmwiki 2.1.3
pmwiki pmwiki 2.0.8
pmwiki pmwiki 2.1.1
pmwiki pmwiki 2.0.9
pmwiki pmwiki 2.0.4
pmwiki pmwiki 2.2.10
pmwiki pmwiki 2.2.14
pmwiki pmwiki 2.2.1
pmwiki pmwiki 2.0.1
pmwiki pmwiki 2.1.26
pmwiki pmwiki 2.2.18
pmwiki pmwiki 2.2.24
pmwiki pmwiki 2.2.3
pmwiki pmwiki 2.2.32
pmwiki pmwiki 2.1.14
pmwiki pmwiki 2.2.2
pmwiki pmwiki 2.1.22
pmwiki pmwiki 2.2.20
pmwiki pmwiki 2.1.2
pmwiki pmwiki 2.1.5
pmwiki pmwiki 2.2.28
pmwiki pmwiki 2.0.10
pmwiki pmwiki 2.1.27
pmwiki pmwiki 2.2.23
pmwiki pmwiki 2.1.12
pmwiki pmwiki 2.1.7
pmwiki pmwiki 2.1.23
pmwiki pmwiki 2.1.16
pmwiki pmwiki 2.2.16
pmwiki pmwiki 2.0.12
pmwiki pmwiki 2.1.9
pmwiki pmwiki 2.0.13
pmwiki pmwiki 2.1.10
pmwiki pmwiki 2.2.9
pmwiki pmwiki 2.0.6
pmwiki pmwiki 2.0.7