{"id":"CVE-2004-2152","details":"Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.","modified":"2026-04-10T03:36:43.178692Z","published":"2004-12-31T05:00:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/12692/"},{"type":"ADVISORY","url":"http://www.osvdb.org/10454"},{"type":"FIX","url":"http://secunia.com/advisories/12692/"},{"type":"FIX","url":"http://sourceforge.net/project/shownotes.php?group_id=34373&release_id=271848"},{"type":"FIX","url":"http://www.osvdb.org/10454"},{"type":"FIX","url":"http://www.securityfocus.com/bid/11302"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17578"}],"schema_version":"1.7.5"}