4.3
CVSSv2

CVE-2007-0857

Published: 08/02/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin prior to 1.5.7 allow remote malicious users to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moinmoin moinmoin 1.5.1

moinmoin moinmoin 1.5.2

moinmoin moinmoin 1.5.5a

moinmoin moinmoin

moinmoin moinmoin 1.5.3_rc2

moinmoin moinmoin 1.5.4

moinmoin moinmoin 1.5.0

moinmoin moinmoin 1.5.5

moinmoin moinmoin 1.5.5_rc1

moinmoin moinmoin 1.5.3

moinmoin moinmoin 1.5.3_rc1

Vendor Advisories

A flaw was discovered in MoinMoin’s page name sanitizer which could lead to a cross-site scripting attack By tricking a user into viewing a crafted MoinMoin page, an attacker could execute arbitrary JavaScript as the current MoinMoin user, possibly exposing the user’s authentication information for the domain where MoinMoin was hosted ...
Debian Bug report logs - #411084 CVE-2007-0901,0902: XSS in debugging information Package: moin; Maintainer for moin is Steve McIntyre <93sam@debianorg>; Reported by: Kees Cook <kees@outfluxnet> Date: Thu, 15 Feb 2007 21:45:02 UTC Severity: grave Tags: patch, security Found in version 134-3 Fixed in version 15 ...
Debian Bug report logs - #410338 CVE-2007-0857: pagename XSS Package: moin; Maintainer for moin is Steve McIntyre <93sam@debianorg>; Reported by: Kees Cook <kees@outfluxnet> Date: Fri, 9 Feb 2007 21:48:02 UTC Severity: critical Tags: fixed-upstream, patch, security, upstream Merged with 410552 Found in version 1 ...