[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1514 moin -- several vulnerabilities

ID: oval:org.mitre.oval:def:7891Date: (C)2009-12-15   (M)2021-06-06
Class: PATCHFamily: unix




Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki. The Common Vulnerabilities and Exposures project identifies the following problems: A cross-site-scripting vulnerability has been discovered in attachment handling. Access control lists for calendars and includes were insufficiently enforced, which could lead to information disclosure. A cross-site-scripting vulnerability has been discovered in the login code. A cross-site-scripting vulnerability has been discovered in attachment handling. A directory traversal vulnerability in cookie handling could lead to local denial of service by overwriting files. Cross-site-scripting vulnerabilities have been discovered in the GUI editor formatter and the code to delete pages. The macro code validates access control lists insufficiently, which could lead to information disclosure.

Platform:
Debian 4.0
Product:
moin
Reference:
DSA-1514
CVE-2007-2423
CVE-2007-2637
CVE-2008-0780
CVE-2008-0781
CVE-2008-0782
CVE-2008-1098
CVE-2008-1099
CVE    7
CVE-2007-2423
CVE-2007-2637
CVE-2008-0781
CVE-2008-0782
...
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies