Last modified: 2010-11-29 16:40:35 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T28164, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 26164 - Potential html injection when the database server isn't available
Potential html injection when the database server isn't available
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
1.17.x
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2010-11-29 16:34 UTC by Platonides
Modified: 2010-11-29 16:40 UTC (History)
0 users

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Platonides 2010-11-29 16:34:06 UTC
Bug for tracking the potential html injection when the database server isn't available fixed in r77422.

Wikis which set $wgServer in their LocalSettings or are in a virtual
host would never be vulnerable.

For sites which show the wiki in the default host, it will depend on how
forgiving is their webserver and php stack for that garbled input, although some kind of foolable proxy —moreover wrongly caching errors (or the default output buffering is disabled and something incorrectly sent a previous text)— would also need to be present in order to make that useful for a potential attacker.
Comment 1 Max Semenik 2010-11-29 16:40:35 UTC
Correction: r77423

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links