Description
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
Remediation
References
Related Vulnerabilities
WordPress Plugin Image Slider by Ays-Responsive Slider and Carousel SQL Injection (2.4.9)
WordPress Plugin Side Cart Woocommerce (Ajax) Cross-Site Request Forgery (2.0)
MySQL Use of Externally-Controlled Format String Vulnerability (CVE-2008-3963)
Microsoft SQL Server Other Vulnerability (CVE-2000-1086)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Cross-Site Scripting (5.6.0.2)