Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T14:37:06.039Z
Reserved: 2007-07-20T00:00:00
Link: CVE-2007-3930
No data.
Status : Deferred
Published: 2007-07-21T00:30:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-3930
No data.
OpenCVE Enrichment
No data.
Weaknesses