CVE-2009-0737
Description
Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple cross-site scripting vulnerabilities exist in MediaWiki's web-based installer, affecting versions before 1.6.12, 1.12.4, and 1.13.4.
Vulnerability
Multiple cross-site scripting (XSS) vulnerabilities exist in the web-based installer (config/index.php) of MediaWiki. These affect versions 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4. The vulnerabilities are only exploitable when the installer is in active use (i.e., it has not been deactivated after installation). The exact vectors are not specified but allow injection of arbitrary web script or HTML [1].
Exploitation
An attacker requires network access to the installer page. No authentication is needed because the installer is typically publicly accessible during setup. The attack can be performed by tricking an administrator into visiting a crafted URL or submitting malicious input while the installer is active. Because the installer may reside on the same domain as an active MediaWiki site, cross-site scripting can be used to attack any web service in the same cookie domain [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the installer page. This can lead to session hijacking, defacement, or theft of sensitive data. If the targeted domain hosts an active wiki, the attacker could potentially compromise administrative sessions, gaining unauthorized access and control over the wiki [1].
Mitigation
Fixed versions were released on February 7, 2009: upgrade to MediaWiki 1.6.12, 1.12.4, or 1.13.4 [1]. If upgrading is not possible, remove or protect the config/ directory after installation, or ensure the installer is never exposed to untrusted networks. The MediaWiki team also advises removing any old, uninstalled copies from the web server to eliminate the attack surface [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
23cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.13.3:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.6.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.wikimedia.org/pipermail/mediawiki-announce/2009-February/000083.htmlnvdPatch
- www.securityfocus.com/bid/33681nvdPatch
- www.vupen.com/english/advisories/2009/0368nvdPatchVendor Advisory
- secunia.com/advisories/33881nvdVendor Advisory
- svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTESnvdVendor Advisory
- svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTESnvdVendor Advisory
- svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTESnvdVendor Advisory
- www.debian.org/security/2009/dsa-1901nvd
News mentions
0No linked articles in our index yet.