Description
Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T14:37:06.039Z
Reserved: 2007-07-20T00:00:00.000Z
Link: CVE-2007-3930
No data.
Status : Modified
Published: 2007-07-21T00:30:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-3930
No data.
OpenCVE Enrichment
No data.
Weaknesses