[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-1098Date: (C)2008-03-05   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain input processed by formatter/text_gedit.py (aka the gui editor formatter); (2) a page name, which triggers an injection in PageEditor.py when the page is successfully deleted by a victim in a DeletePage action; or (3) the destination page name for a RenamePage action, which triggers an injection in PageEditor.py when a victim's rename attempt fails because of a duplicate name. NOTE: the AttachFile XSS issue is already covered by CVE-2008-0781, and the login XSS issue is already covered by CVE-2008-0780.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-28173
SECUNIA-29262
SECUNIA-29444
SECUNIA-30031
SECUNIA-33755
DSA-1514
FEDORA-2008-3301
FEDORA-2008-3328
GLSA-200803-27
USN-716-1
http://hg.moinmo.in/moin/1.5/rev/4ede07e792dd
http://hg.moinmo.in/moin/1.5/rev/d0152eeb4499
http://moinmo.in/SecurityFixes
moinmoin-multiple-actions-xss(41037)

CWE    1
CWE-79
OVAL    2
oval:org.mitre.oval:def:7891
oval:org.secpod.oval:def:700313

© SecPod Technologies