Security Advisory

CVE-2006-7223

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-09-14 00:00:00
Last updated 2024-09-16 19:45:40
Assigner mitre
State PUBLISHED

Description

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.