VYPR
Unrated severityNVD Advisory· Published Feb 25, 2009· Updated Apr 23, 2026

CVE-2009-0737

CVE-2009-0737

Description

Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple cross-site scripting vulnerabilities exist in MediaWiki's web-based installer, affecting versions before 1.6.12, 1.12.4, and 1.13.4.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in the web-based installer (config/index.php) of MediaWiki. These affect versions 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4. The vulnerabilities are only exploitable when the installer is in active use (i.e., it has not been deactivated after installation). The exact vectors are not specified but allow injection of arbitrary web script or HTML [1].

Exploitation

An attacker requires network access to the installer page. No authentication is needed because the installer is typically publicly accessible during setup. The attack can be performed by tricking an administrator into visiting a crafted URL or submitting malicious input while the installer is active. Because the installer may reside on the same domain as an active MediaWiki site, cross-site scripting can be used to attack any web service in the same cookie domain [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the installer page. This can lead to session hijacking, defacement, or theft of sensitive data. If the targeted domain hosts an active wiki, the attacker could potentially compromise administrative sessions, gaining unauthorized access and control over the wiki [1].

Mitigation

Fixed versions were released on February 7, 2009: upgrade to MediaWiki 1.6.12, 1.12.4, or 1.13.4 [1]. If upgrading is not possible, remove or protect the config/ directory after installation, or ensure the installer is never exposed to untrusted networks. The MediaWiki team also advises removing any old, uninstalled copies from the web server to eliminate the attack surface [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

23
  • MediaWiki/Mediawiki23 versions
    cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*+ 22 more
    • cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.13.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.6.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.