{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T13:21:06.168","vulnerabilities":[{"cve":{"id":"CVE-2008-5250","sourceIdentifier":"cve@mitre.org","published":"2008-12-19T17:30:03.110","lastModified":"2025-04-09T00:30:58.490","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an SVG scripting browser is used and SVG uploads are enabled, allows remote authenticated users to inject arbitrary web script or HTML by editing a wiki page."},{"lang":"es","value":"Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en versiones de MediaWiki anteriores a  1.6.11, 1.12.x anteriores a 1.12.2, y 1.13.3 anteriores a 1.13.x, cuando se esta usando Internet Explorer y las subidas están habilitadas, o bien cuando un navegador que permita secuencias de comandos SVG se este usando y las subidas SVG estén habilitadas, permite a usuarios remotos autenticados inyectar HTML o secuencias de comandos web arbitrarias  durante la edición de una página del wiki."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.6.11:*:*:*:*:*:*:*","matchCriteriaId":"9842D148-50D2-4A52-A3E1-529670A25EBD"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*","matchCriteriaId":"746023B5-2472-4FC9-BEDF-FE6A321F12B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*","matchCriteriaId":"66714539-F1E1-4C16-AA12-059EEB1B9DF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*","matchCriteriaId":"79CDE6D3-A26D-4ECD-B949-B9DDB53F67C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*","matchCriteriaId":"A26F4C94-E3A5-456E-8E5E-36BA67DD4BD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*","matchCriteriaId":"C7C6D23B-B5C1-4F10-9F62-E81F639FF40F"}]}]}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html","source":"cve@mitre.org"},{"url":"http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://secunia.com/advisories/33133","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://secunia.com/advisories/33349","source":"cve@mitre.org"},{"url":"http://www.debian.org/security/2009/dsa-1901","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/32844","source":"cve@mitre.org"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html","source":"cve@mitre.org"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html","source":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://secunia.com/advisories/33133","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://secunia.com/advisories/33349","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.debian.org/security/2009/dsa-1901","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/32844","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}