---
title: "CVE-2008-5250\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-5250?format=md
keywords: index, follow
---

# CVE-2008-5250

Publication date 19 December 2008

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x
before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and
uploads are enabled, or an SVG scripting browser is used and SVG uploads
are enabled, allows remote authenticated users to inject arbitrary web
script or HTML by editing a wiki page.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mediawiki | 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Fixed 1:1.12.0-2ubuntu0.2 |
| 8.04 LTS hardy | Fixed 1:1.11.2-2ubuntu0.2 |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5250)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-5250)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-5250)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-5250)

### Other references

* <http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508868>
* <https://www.cve.org/CVERecord?id=CVE-2008-5250>
