{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2010-06-08T00:30:01Z",
  "id": "CVE-2010-1647",
  "details": "Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.",
  "references": [
    {
      "type": "REPORT",
      "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=23687"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html"
    }
  ]
}
