Description
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
Remediation
References
Related Vulnerabilities
Ruby Improper Input Validation Vulnerability (CVE-2015-1855)
Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965)
Joomla! Core 1.0.x Session Fixation (1.0.0 - 1.0.12)
Ruby on Rails Improper Access Control Vulnerability (CVE-2016-6317)
Oracle Database Server CVE-2013-3789 Vulnerability (CVE-2013-3789)