CVE-2009-0260 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).
Reference
http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1 http://moinmo.in/SecurityFixesmoin1.8.1 http://osvdb.org/51485 http://secunia.com/advisories/33593 http://secunia.com/advisories/33716 http://secunia.com/advisories/33755 http://www.securityfocus.com/archive/1/500197/100/0/threaded http://www.securityfocus.com/bid/33365 http://www.vupen.com/english/advisories/2009/0195 https://exchange.xforce.ibmcloud.com/vulnerabilities/48126 https://usn.ubuntu.com/716-1/ https://www.debian.org/security/2009/dsa-1715
Share on: