Softver
moinmoin
Aggregate across all detected versions
Ukupno hostova
0
distinct hosts
Versions Seen
0
Countries
0
Poznate CVE ranjivosti
43
known CVEs
Top države
No geolocated hosts.
Top ASN-ovi
No attributed hosts.
CVE podudaranja
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2004-1463 | 10.0 | HIGH | Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact. |
| CVE-2020-25074 | 9.8 | N/A | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments... |
| CVE-2020-15275 | 8.7 | N/A | MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This... |
| CVE-2004-0708 | 7.5 | HIGH | MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges. |
| CVE-2004-1462 | 7.5 | HIGH | Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) de... |
| CVE-2009-4762 | 7.5 | HIGH | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allow... |
| CVE-2010-0669 | 7.5 | HIGH | MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors. |
| CVE-2010-0717 | 7.5 | HIGH | The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact an... |
| CVE-2008-1937 | 6.8 | MEDIUM | The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows re... |
| CVE-2008-6603 | 6.8 | MEDIUM | MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access res... |
| CVE-2010-0668 | 6.8 | MEDIUM | Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configur... |
| CVE-2012-6080 | 6.4 | MEDIUM | Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows rem... |
| CVE-2016-7146 | 6.1 | N/A | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site... |
| CVE-2016-7148 | 6.1 | N/A | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)... |
| CVE-2016-9119 | 6.1 | N/A | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or H... |
| CVE-2017-5934 | 6.1 | N/A | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or... |
| CVE-2012-4404 | 6.0 | MEDIUM | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," w... |
| CVE-2012-6081 | 6.0 | MEDIUM | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin bef... |
| CVE-2012-6495 | 6.0 | MEDIUM | Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1... |
| CVE-2007-2423 | 5.8 | MEDIUM | Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in a... |
| CVE-2007-0902 | 5.0 | MEDIUM | Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information. NOTE: the prov... |
| CVE-2007-2637 | 5.0 | MEDIUM | MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors. |
| CVE-2008-0782 | 5.0 | MEDIUM | Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID i... |
| CVE-2008-1099 | 5.0 | MEDIUM | _macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages. |
| CVE-2008-6548 | 5.0 | MEDIUM | The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via... |
| CVE-2008-6549 | 5.0 | MEDIUM | The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which... |
| CVE-2010-0667 | 5.0 | MEDIUM | MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, wh... |
| CVE-2010-1238 | 5.0 | MEDIUM | MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have empty valu... |
| CVE-2007-0857 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info... |
| CVE-2007-0901 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hi... |
| CVE-2008-0780 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML v... |
| CVE-2008-0781 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script... |
| CVE-2008-1098 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain... |
| CVE-2008-3381 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary... |
| CVE-2009-0260 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HT... |
| CVE-2009-0312 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary we... |
| CVE-2009-1482 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script... |
| CVE-2010-2487 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote attackers to inject a... |
| CVE-2010-2969 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject arbitrary web script... |
| CVE-2010-2970 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted con... |