Description
MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Remediation
References
Related Vulnerabilities
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5488)
WordPress Cookie Data PHP Code Injection Vulnerability (1.5 - 1.5.1.3)
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.11.19)
Oracle Database Server CVE-2013-1534 Vulnerability (CVE-2013-1534)